Vulnerability Description
Windows binaries generated with InstallBuilder versions earlier than 19.7.0 are vulnerable to tampering even if they contain a valid Authenticode signature.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitrock | Installbuilder | < 19.7.0 |
References
- https://blog.bitrock.com/2019/08/installer-tampering-while-preserving.htmlThird Party Advisory
- https://blog.bitrock.com/2019/08/installer-tampering-while-preserving.htmlThird Party Advisory
FAQ
What is CVE-2019-5530?
CVE-2019-5530 is a vulnerability with a CVSS score of 7.8 (HIGH). Windows binaries generated with InstallBuilder versions earlier than 19.7.0 are vulnerable to tampering even if they contain a valid Authenticode signature.
How severe is CVE-2019-5530?
CVE-2019-5530 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5530?
Check the references section above for vendor advisories and patch information. Affected products include: Bitrock Installbuilder.