PT-2018-4841 · Microsoft · Wix Toolset
Published
2018-06-04
·
Updated
2020-06-17
·
CVE-2016-10663
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
wixtoolset (affected versions not specified)
Description
The wixtoolset is vulnerable to man-in-the-middle (MITM) attacks due to downloading binary resources over HTTP. This could lead to remote code execution (RCE) if an attacker intercepts the response and replaces the executable with a malicious one. The vulnerability can be exploited when an attacker has a privileged network position.
Recommendations
To mitigate the issue, avoid using the wixtoolset package if possible, and consider using a different package instead.
As a temporary workaround, ensure that the package is not installed while connected to a public network to reduce the risk of exploitation.
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wix Toolset