CVE-2020-3979
VMware InstallBuilder for Qt vulnerability analysis and mitigation

Overview

CVE-2020-3979 is a DLL planting vulnerability that affects InstallBuilder for Qt Windows installers. The vulnerability was discovered and fixed in InstallBuilder version 20.7.0, released on August 21, 2020 (InstallBuilder Blog).

Technical details

The vulnerability exists because InstallBuilder for Qt Windows installers search for plugins at a predictable location during initialization time, which is writable by non-admin users. While these plugins are not required for operation, they are automatically loaded if present. This behavior could allow an attacker to plant a malicious library, potentially resulting in code execution within the security scope of the installer (InstallBuilder Blog).

Impact

If exploited, this vulnerability could allow an attacker to execute malicious code with the security scope of the installer. However, the attack requires previous access to the machine to plant the malicious library before the vulnerable installer is executed (InstallBuilder Blog).

Exploitability

The vulnerability requires an attacker to have prior access to the target machine to plant a malicious library in a specific location before the vulnerable installer is executed. This prerequisite somewhat limits the exploitability of the vulnerability (InstallBuilder Blog).

Mitigation and workarounds

The vulnerability was fixed in InstallBuilder version 20.7.0. Affected InstallBuilder for Qt customers are advised to update to InstallBuilder 20.7.0 or later and release new versions of their installers (InstallBuilder Blog).

Community reactions

The vulnerability was responsibly disclosed by Hou JingYi (@hjy79425575) of Qihoo 360 CERT (InstallBuilder Blog).

Additional resources


SourceThis report was generated using AI

Related VMware InstallBuilder for Qt vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-3979HIGH7.8
  • VMware InstallBuilder for Qt logoVMware InstallBuilder for Qt
  • cpe:2.3:a:installbuilder:installbuilder:*:*:*:*:*:qt:*:*
NoYesSep 18, 2020
CVE-2022-31694HIGH7.3
  • VMware InstallBuilder for Qt logoVMware InstallBuilder for Qt
  • cpe:2.3:a:installbuilder:installbuilder:*:*:*:*:*:qt:*:*
NoYesNov 18, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management