CVE-2024-29188

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-29188
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29188.json
Aliases
Published
2024-03-24T20:15:08Z
Modified
2024-03-26T01:16:59.336398Z
Details

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's RemoveFolderEx functionality could allow a standard user to delete protected directories. RemoveFolderEx deletes an entire directory tree during installation or uninstallation. It does so by recursing every subdirectory starting at a specified directory and adding each subdirectory to the list of directories Windows Installer should delete. If the setup author instructed RemoveFolderEx to delete a per-user folder from a per-machine installer, an attacker could create a directory junction in that per-user folder pointing to a per-machine, protected directory. Windows Installer, when executing the per-machine installer after approval by an administrator, would delete the target of the directory junction. This vulnerability is fixed in 3.14.1 and 4.0.5.

References

Affected packages

Git / github.com/wixtoolset/wix

Affected ranges

Type
GIT
Repo
https://github.com/wixtoolset/wix
Events
Introduced
0The exact introduced commit is unknown
Fixed
Type
GIT
Repo
https://github.com/wixtoolset/wix3
Events
Introduced
0The exact introduced commit is unknown
Fixed

Affected versions

Other

wix3101rtm
wix3102rtm
wix3103rtm
wix310rtm
wix311rtm
wix314rtm
wix38rtm
wix39rtm