Vulnerability Bulletins

IBM Security Bulletin: InstallShield generates installation executables which are vulnerable to an DLL-planting vulnerability affect AppScan Standard (CVE-2016-2542)

   
Affected software IBM
 
Flexera InstallShield could allow a remote attacker to execute arbitrary code on the system. The application does not directly specify the fully qualified path to a dynamic-linked library (schannel.dll) when running on Microsoft Windows. By persuading a victim to open a specially-crafted file from a WebDAV or SMB share using a vulnerable application, a remote attacker could exploit this vulnerability via a specially-crafted library to execute arbitrary code on the system.CVE(s):

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_installshield_generates_installation_executables_which_are_vulnerable_to_an_dll_planting_vulnerability_affect_appscan_standard_cve_2016_2542?lang=en_us