Headline
CVE-2023-25396: Advanced Installer 20.1 - Release Notes
Privilege escalation in the MSI repair functionality in Caphyon Advanced Installer 20.0 and below allows attackers to access and manipulate system files.
Advanced Installer 20.1 Release Notes
On November 16th, 2022 Caphyon Ltd. is proud to announce the release of Advanced Installer 20.1 in Free, Professional, Enterprise and Architect editions. This release is available for download on the Advanced Installer website.
Starting with version 20 of Advanced Installer, you are able to download and install prerequisites in parallel.
Once the first prerequisite is completely downloaded its installation begins while additional prerequisites continue to be downloaded, resulting in a faster installation of the application.
You can even customize the installer to include a modern progress bar. As a result, every user will be aware of the status of both the download and installation processes, as well as which prerequisite is currently downloading or installing.
Watch the video below to learn how to download and install prerequisites in parallel:
New features, bug fixes, and general improvements are included in the current release. See the full list below.
Enhancements
Requested by customerBitness detection in the Office applications launch condition
Requested by customerPowerShell Automation for Operations property for predefined folder
Updated MSIX schema for 22H2
Requested by customerNew option to retrieve version from Assembly version
Requested by customerImproved the warning message regarding duplicate filenames for TXT updates
Predefined prerequisites for .NET 7.0
Update “Java Development Kit” launch condition to the latest version “Java SE 19”
Update .NET and .NET Core prerequisites to the latest version (6.0.11 & 3.1.31)
Bug fixes
Scheduled task installation fails when launched under the system account
Local privilege escalation via MSI installer Repair mode
Reported by customerSettings.ais vulnerability during Repair on advinst.msi - exploit that gains system account privileges
Folder Redirections are not added automatically when importing a .RPK file
Fixed the download link for Microsoft WebView2 predefined prerequisite
Reported by customerHandle JSON empty values for properties with numeric type
Reported by customerWhen the password argument is absent but previously saved in the project, the “/SetDigitalCertificateFile” command line returns an error
Reported by customer“InstallTypeDlg” overwrites the path with the default one
Reported by customerThe “ProgressPrereqDlg” dialog is not successfully rendered on Spring theme
Reported by customerProperties are no longer configurable in a merge module project after they were moved to the new “Properties” view
The project is not marked as modified after CN synchronization
Reported by customerStart Powershell Script fails when PowerShell 2.0 is disabled
Crash when creating a new project after searching for a reference
The repackager fails to load the custom profiles from the new repository location
Reported by customerInstallShield Project Import fails during Binary Table Import
Reported by customerRegistry with a 64-bit component is never preserved in a 32-bit package
The Trace option for PSF does not log any information in the console log