CVE-2024-29188 – wix
Package
Manager: nuget
Name: wix
Vulnerable Version: >=0 <3.14.1 || >=4.0.0 <4.0.5
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00026 pctl0.05421
Details
Malicious directory junction can cause WiX RemoveFoldersEx to possibly delete elevated files ### Summary The custom action behind WiX's `RemoveFolderEx` functionality could allow a standard user to delete protected directories. ### Details `RemoveFolderEx` deletes an entire directory tree during installation or uninstallation. It does so by recursing every subdirectory starting at a specified directory and adding each subdirectory to the list of directories Windows Installer should delete. If the setup author instructed `RemoveFolderEx` to delete a per-user folder from a per-machine installer, an attacker could create a directory junction in that per-user folder pointing to a per-machine, protected directory. Windows Installer, when executing the per-machine installer after approval by an administrator, would delete the target of the directory junction.
Metadata
Created: 2024-03-25T19:42:17Z
Modified: 2024-03-25T19:42:17Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-jx4p-m4wm-vvjg/GHSA-jx4p-m4wm-vvjg.json
CWE IDs: ["CWE-59"]
Alternative ID: GHSA-jx4p-m4wm-vvjg
Finding: F076
Auto approve: 1