CVE-2024-24810

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-24810
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24810.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-24810
Aliases
Published
2024-02-07T03:15:50Z
Modified
2024-09-02T20:21:13Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges. This impacts any installer built with the WiX installer framework. This issue has been patched in version 4.0.4.

References

Affected packages

Git / github.com/wixtoolset/wix

Affected ranges

Type
GIT
Repo
https://github.com/wixtoolset/wix
Events