<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:30:29.542784+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04608</id>
    <title>bdu:2024-04608</title>
    <updated>2026-10-03T22:30:29.646592+00:00</updated>
    <content>bdu:2024-04608</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04608"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0489</id>
    <title>certfr-2024-avi-0489 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-03T22:30:29.646632+00:00</updated>
    <content>certfr-2024-avi-0489</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0489"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-158347</id>
    <title>EUVD-2026-158347</title>
    <updated>2026-10-03T22:30:29.646653+00:00</updated>
    <content>EUVD-2026-158347</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-158347"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-29187</id>
    <title>fkie_cve-2024-29187</title>
    <updated>2026-10-03T22:30:29.646667+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points to an insecure directory C:\Windows\Temp to drop and load multiple binaries. Standard users can hijack the binary before it's loaded in the application resulting in elevation of privileges. This vulnerability is fixed in 3.14.1 and 4.0.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-29187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rf39-3f98-xr7r</id>
    <title>GHSA-rf39-3f98-xr7r — WiX based installers are vulnerable to binary hijack when run as SYSTEM</title>
    <updated>2026-10-03T22:30:29.646700+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: wix, NuGet: WixToolset.Sdk</p>
<p>### Summary
Burn uses an unprotected C:\Windows\Temp directory to copy binaries and run them from there. This directory is not entirely protected against low privilege users.</p>
<p>### Details
When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points to an insecure directory C:\Windows\Temp to drop and load multiple binaries. Standard users can hijack the binary before it's loaded in the application resulting in elevation of privileges.</p>
<p>icacls c:\windows\temp</p>
<p>**BUILTIN\Users:(CI)(S,WD,AD,X)** 
BUILTIN\Administrators:(F)
BUILTIN\Administrators:(OI)(CI)(IO)(F)
NT AUTHORITY\SYSTEM:(F)
NT AUTHORITY\SYSTEM:(OI)(CI)(IO)(F)
 CREATOR OWNER:(OI)(CI)(IO)(F)
                
Built in users(non-administrators) have special permissions to this folder and can create files and write to this directory. While they do not have explicit read permissions, there is a way they can monitor the changes to this directory using ReadDirectoryChangesW API and thus figure out randomized folder names created inside this directory as wel</p>
<p>### PoC</p>
<p>PoC works against the against visual studio enterprise with update 3 [installer ](https://myvs.download.prss.microsoft.com/dbazure/en_visual_studio_enterprise_2015_with_update_3_x86_x64_dvd_8923288.iso?t=8132cd54-4b83-4478-8b73-fd9eb93437bf&amp;P1=1709239640&amp;P2=601&amp;P3=2&amp;P4=iorgKPv%2bG8n2NANTPUVoB92rr8t3W4XM594%2f9BtQQJrYrr8SwxGDxV%2fj%2f2F6Ulto0bXrIaFoZUr4yV37YAsOZVpM29IMtQEO0673AbDVuTe93qDb6wb7xdlpZSse0LZURUwwIFw5cwHQS2ZtvkunXE0osgXtEBT2IzVbPwVH39%…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rf39-3f98-xr7r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-29187</id>
    <title>gsd-2024-29187</title>
    <updated>2026-10-03T22:30:29.646752+00:00</updated>
    <content>gsd-2024-29187</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-29187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-021</id>
    <title>VDE-2024-021 — WAGO: Vulnerability in WAGO Navigator</title>
    <updated>2026-10-03T22:30:29.646765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The WAGO Navigator versions 1.0.1 and 1.0 are vulnerable due to the use of the WiX toolset version 3.11.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1338</id>
    <title>WID-SEC-W-2024-1338 — Microsoft Visual Studio: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:30:29.646784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio 2017, Microsoft Visual Studio 2019 und Microsoft Visual Studio 2022 ausnutzen, um seine Privilegien zu erhöhen oder beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1338"/>
  </entry>
</feed>
