CVE-2024-24810
WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges. This impacts any installer built with the WiX installer framework. This issue has been patched in version 4.0.4.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 0.24%
- CWE
- CWE-426
- Published
- 2024-02-07
- Last modified
- 2026-03-13
Affected products
- wixtoolset issues
Weakness type
Related vulnerabilities
- CVE-2026-0307 — GlobalProtect App: Local Privilege Escalation Vulnerabilities
- CVE-2026-80159 — Acrobat Reader | Untrusted Search Path (CWE-426)
- CVE-2026-81192 — OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
- CVE-2026-78574 — Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling
- CVE-2026-69785 — Windows Smart Card Elevation of Privilege Vulnerability
- CVE-2026-69328 — Windows Storage Elevation of Privilege Vulnerability
- CVE-2026-84226 — OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local...
- CVE-2026-82862 — Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files