CVE-2025-12418

Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a local administrator performs an uninstall, a symlink may get followed on removal of a user writeable configuration directory and induce a Denial of Service as a result. The issue is resolved through the hotfixes InstallShield2025R1-CVE-2025-12418-SecurityPatch, InstallShield2024R2-CVE-2025-12418-SecurityPatch, and InstallShield2023R2-CVE-2025-12418-SecurityPatch.
CVSS

No CVSS.

Configurations

No configuration.

History

07 Nov 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-07 22:15

Updated : 2025-11-12 16:20


NVD link : CVE-2025-12418

Mitre link : CVE-2025-12418

CVE.ORG link : CVE-2025-12418


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')