WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points to an insecure directory C:\Windows\Temp to drop and load multiple binaries. Standard users can hijack the binary before it's loaded in the application resulting in elevation of privileges. This vulnerability is fixed in 3.14.1 and 4.0.5.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.10 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.6 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.8 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.4 version stream, or upgrade to a newer supported version of Visual Studio 2022. | Jun 25, 2025 | Jun 11, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub