W
iX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges. This impacts any installer built with the WiX installer framework. This issue has been patched in version 4.0.4.
References
| Link | Resource |
|---|---|
| https://github.com/wixtoolset/issues/security/advisories/GHSA-7wh2-wxc7-9ph5 | Vendor Advisory |
| https://github.com/wixtoolset/issues/security/advisories/GHSA-7wh2-wxc7-9ph5 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:59
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
| References | () https://github.com/wixtoolset/issues/security/advisories/GHSA-7wh2-wxc7-9ph5 - Vendor Advisory |
Information
Published : 2024-02-07 03:15
Updated : 2024-11-21 08:59
NVD link : CVE-2024-24810
Mitre link : CVE-2024-24810
CVE.ORG link : CVE-2024-24810
JSON object : View
Products Affected
CWE
CWE-426
Untrusted Search Path