VDB
Sign up
HIGH7.9

GHSA-jx4p-m4wm-vvjg

Malicious directory junction can cause WiX RemoveFoldersEx to possibly delete elevated files

Quick fix

GHSA-jx4p-m4wm-vvjg — wix: upgrade to the fixed version with the command below.

dotnet add package wix --version 3.14.1

Details

### Summary The custom action behind WiX's `RemoveFolderEx` functionality could allow a standard user to delete protected directories.

### Details `RemoveFolderEx` deletes an entire directory tree during installation or uninstallation. It does so by recursing every subdirectory starting at a specified directory and adding each subdirectory to the list of directories Windows Installer should delete. If the setup author instructed `RemoveFolderEx` to delete a per-user folder from a per-machine installer, an attacker could create a directory junction in that per-user folder pointing to a per-machine, protected directory. Windows Installer, when executing the per-machine installer after approval by an administrator, would delete the target of the directory junction.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/wix
Introduced in: 0Fixed in: 3.14.1
Fixdotnet add package wix --version 3.14.1
NuGet/wix
Introduced in: 4.0.0Fixed in: 4.0.5
Fixdotnet add package wix --version 4.0.5
NuGet/WixToolset.Util.wixext
Introduced in: 0Fixed in: 4.0.5
Fixdotnet add package WixToolset.Util.wixext --version 4.0.5

References