{"id":"GHSA-rf39-3f98-xr7r","summary":"WiX based installers are vulnerable to binary hijack when run as SYSTEM","details":"### Summary\nBurn uses an unprotected C:\\Windows\\Temp directory to copy binaries and run them from there. This directory is not entirely protected against low privilege users. \n\n### Details\nWhen a bundle runs as SYSTEM user, Burn uses GetTempPathW which points to an insecure directory C:\\Windows\\Temp to drop and load multiple binaries. Standard users can hijack the binary before it's loaded in the application resulting in elevation of privileges.\n\nicacls c:\\windows\\temp\n\n   **BUILTIN\\Users:(CI)(S,WD,AD,X)** \nBUILTIN\\Administrators:(F)\nBUILTIN\\Administrators:(OI)(CI)(IO)(F)\nNT AUTHORITY\\SYSTEM:(F)\nNT AUTHORITY\\SYSTEM:(OI)(CI)(IO)(F)\n CREATOR OWNER:(OI)(CI)(IO)(F)\n                \nBuilt in users(non-administrators) have special permissions to this folder and can create files and write to this directory. While they do not have explicit read permissions, there is a way they can monitor the changes to this directory using ReadDirectoryChangesW API and thus figure out randomized folder names created inside this directory as wel\n \n\n### PoC\n\n PoC works against the against visual studio enterprise with update 3 [installer ](https://myvs.download.prss.microsoft.com/dbazure/en_visual_studio_enterprise_2015_with_update_3_x86_x64_dvd_8923288.iso?t=8132cd54-4b83-4478-8b73-fd9eb93437bf&P1=1709239640&P2=601&P3=2&P4=iorgKPv%2bG8n2NANTPUVoB92rr8t3W4XM594%2f9BtQQJrYrr8SwxGDxV%2fj%2f2F6Ulto0bXrIaFoZUr4yV37YAsOZVpM29IMtQEO0673AbDVuTe93qDb6wb7xdlpZSse0LZURUwwIFw5cwHQS2ZtvkunXE0osgXtEBT2IzVbPwVH39%2fum854xb4e2Dp61wgNrMZcOLLluBbeA3KX1sP3mm7WAWXBvlFiQWEnTfR5XH5mlLyPy2qfqCXWCjl84jNX7uY%2bpLR1IbfeD2JlcIQNeW2QrvmmqRrRbGvvaCA97IaSjM16XcDqVjvAEGW3sWXUc7y%2fEf68WZIyT7iilaEDUvaqqA%3d%3d&su=1)\n\n#### Reproduction steps\nAs a standard user, run the poc.\nMount the iso and run visual studio installer as local system account.\nThe PoC should hijack the the binaries dropped by vs installer and a child process \"notepad.exe\" will be running.\n\n### Impact\nThis is an Elevation of Privilege Vulnerability where a low privileged user can hijack binaries in an unprotected path C:\\Windows\\Temp to elevate to the SYSTEM user privileges. ","aliases":["CVE-2024-29187"],"modified":"2026-09-10T03:50:11.017919006Z","published":"2024-03-25T19:42:32Z","database_specific":{"nvd_published_at":"2024-03-24T20:15:08Z","cwe_ids":["CWE-732"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-03-25T19:42:32Z"},"references":[{"type":"WEB","url":"https://github.com/wixtoolset/issues/security/advisories/GHSA-rf39-3f98-xr7r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29187"},{"type":"WEB","url":"https://github.com/wixtoolset/wix/commit/75a8c75d4e02ea219008dc5af7d03869291d61f7"},{"type":"WEB","url":"https://github.com/wixtoolset/wix3/commit/6d372e5169f1a334a395cdf496443bc0732098e9"},{"type":"PACKAGE","url":"https://github.com/wixtoolset/issues"}],"affected":[{"package":{"name":"wix","ecosystem":"NuGet","purl":"pkg:nuget/wix"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.14.1"}]}],"versions":["3.10.0","3.10.0.1719-pre","3.10.0.1726-pre","3.10.0.2103-pre","3.10.0.2103-pre1","3.10.1","3.10.2","3.10.3","3.10.4","3.11.0","3.11.0.1507-rc","3.11.0.1528-rc2","3.11.0.321-pre","3.11.0.504-pre","3.11.0.906-pre","3.11.1","3.11.2","3.14.0","3.6.0","3.6.0.1","3.7.0","3.7.0.1","3.8.0","3.8.0.1","3.9.0","3.9.0.1","3.9.2","3.9.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-rf39-3f98-xr7r/GHSA-rf39-3f98-xr7r.json"}},{"package":{"name":"wix","ecosystem":"NuGet","purl":"pkg:nuget/wix"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.5"}]}],"versions":["4.0.0","4.0.0.2926-pre","4.0.0.3226-pre","4.0.0.3922-pre","4.0.0.4506-pre","4.0.0.5512-pre","4.0.1","4.0.2","4.0.3","4.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-rf39-3f98-xr7r/GHSA-rf39-3f98-xr7r.json"}},{"package":{"name":"WixToolset.Sdk","ecosystem":"NuGet","purl":"pkg:nuget/WixToolset.Sdk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.5"}]}],"versions":["4.0.0","4.0.1","4.0.2","4.0.3","4.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-rf39-3f98-xr7r/GHSA-rf39-3f98-xr7r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}