CVE-2021-27766

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
06/05/2022
Last modified:
16/05/2022

Description

The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:* 9.5 (including) 9.5.18 (including)
cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:* 10 (including) 10.0.5 (including)