PT-2018-4841 · Microsoft · Wix Toolset

Published

2018-06-04

·

Updated

2020-06-17

·

CVE-2016-10663

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions wixtoolset (affected versions not specified)
Description The wixtoolset is vulnerable to man-in-the-middle (MITM) attacks due to downloading binary resources over HTTP. This could lead to remote code execution (RCE) if an attacker intercepts the response and replaces the executable with a malicious one. The vulnerability can be exploited when an attacker has a privileged network position.
Recommendations To mitigate the issue, avoid using the wixtoolset package if possible, and consider using a different package instead. As a temporary workaround, ensure that the package is not installed while connected to a public network to reduce the risk of exploitation.

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10663
GHSA-CR8H-X88H-JWJ2

Affected Products

Wix Toolset