
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-3979 is a DLL planting vulnerability that affects InstallBuilder for Qt Windows installers. The vulnerability was discovered and fixed in InstallBuilder version 20.7.0, released on August 21, 2020 (InstallBuilder Blog).
The vulnerability exists because InstallBuilder for Qt Windows installers search for plugins at a predictable location during initialization time, which is writable by non-admin users. While these plugins are not required for operation, they are automatically loaded if present. This behavior could allow an attacker to plant a malicious library, potentially resulting in code execution within the security scope of the installer (InstallBuilder Blog).
If exploited, this vulnerability could allow an attacker to execute malicious code with the security scope of the installer. However, the attack requires previous access to the machine to plant the malicious library before the vulnerable installer is executed (InstallBuilder Blog).
The vulnerability requires an attacker to have prior access to the target machine to plant a malicious library in a specific location before the vulnerable installer is executed. This prerequisite somewhat limits the exploitability of the vulnerability (InstallBuilder Blog).
The vulnerability was fixed in InstallBuilder version 20.7.0. Affected InstallBuilder for Qt customers are advised to update to InstallBuilder 20.7.0 or later and release new versions of their installers (InstallBuilder Blog).
The vulnerability was responsibly disclosed by Hou JingYi (@hjy79425575) of Qihoo 360 CERT (InstallBuilder Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."