Description

Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a local administrator performs an uninstall, a symlink may get followed on removal of a user writeable configuration directory and induce a Denial of Service as a result. The issue is resolved through the hotfixes InstallShield2025R1-CVE-2025-12418-SecurityPatch, InstallShield2024R2-CVE-2025-12418-SecurityPatch, and InstallShield2023R2-CVE-2025-12418-SecurityPatch.

INFO

Published Date :

2025-11-07T21:27:04.650Z

Last Modified :

2025-11-07T21:27:04.650Z

Source :

flexera
AFFECTED PRODUCTS

The following products are affected by CVE-2025-12418 vulnerability.

Vendors Products
Revenera
  • Installshield
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-12418.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability