<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:48:47 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-04608</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04608</link>
      <description>bdu:2024-04608</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04608</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0489 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0489</link>
      <description>certfr-2024-avi-0489</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0489</guid>
    </item>
    <item>
      <title>EUVD-2026-158347</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-158347</link>
      <description>EUVD-2026-158347</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-158347</guid>
    </item>
    <item>
      <title>fkie_cve-2024-29187</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-29187</link>
      <description>&lt;p&gt;WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points to an insecure directory C:\Windows\Temp to drop and load multiple binaries. Standard users can hijack the binary before it&amp;#39;s loaded in the application resulting in elevation of privileges. This vulnerability is fixed in 3.14.1 and 4.0.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points to an insecure directory C:\Windows\Temp to drop and load multiple binaries. Standard users can hijack the binary before it&amp;#39;s loaded in the application resulting in elevation of privileges. This vulnerability is fixed in 3.14.1 and 4.0.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-29187</guid>
    </item>
    <item>
      <title>GHSA-rf39-3f98-xr7r — WiX based installers are vulnerable to binary hijack when run as SYSTEM</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rf39-3f98-xr7r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: wix, NuGet: WixToolset.Sdk&lt;/p&gt;
&lt;p&gt;### Summary
Burn uses an unprotected C:\Windows\Temp directory to copy binaries and run them from there. This directory is not entirely protected against low privilege users.&lt;/p&gt;
&lt;p&gt;### Details
When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points to an insecure directory C:\Windows\Temp to drop and load multiple binaries. Standard users can hijack the binary before it&amp;#39;s loaded in the application resulting in elevation of privileges.&lt;/p&gt;
&lt;p&gt;icacls c:\windows\temp&lt;/p&gt;
&lt;p&gt;**BUILTIN\Users:(CI)(S,WD,AD,X)** 
BUILTIN\Administrators:(F)
BUILTIN\Administrators:(OI)(CI)(IO)(F)
NT AUTHORITY\SYSTEM:(F)
NT AUTHORITY\SYSTEM:(OI)(CI)(IO)(F)
 CREATOR OWNER:(OI)(CI)(IO)(F)
                
Built in users(non-administrators) have special permissions to this folder and can create files and write to this directory. While they do not have explicit read permissions, there is a way they can monitor the changes to this directory using ReadDirectoryChangesW API and thus figure out randomized folder names created inside this directory as wel&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;PoC works against the against visual studio enterprise with update 3 [installer ](https://myvs.download.prss.microsoft.com/dbazure/en_visual_studio_enterprise_2015_with_update_3_x86_x64_dvd_8923288.iso?t=8132cd54-4b83-4478-8b73-fd9eb93437bf&amp;amp;P1=1709239640&amp;amp;P2=601&amp;amp;P3=2&amp;amp;P4=iorgKPv%2bG8n2NANTPUVoB92rr8t3W4XM594%2f9BtQQJrYrr8SwxGDxV%2fj%2f2F6Ulto0bXrIaFoZUr4yV37YAsOZVpM29IMtQEO0673AbDVuTe93qDb6wb7xdlpZSse0LZURUwwIFw5cwHQS2ZtvkunXE0osgXtEBT2IzVbPwVH39%…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: wix, NuGet: WixToolset.Sdk&lt;/p&gt;
&lt;p&gt;### Summary
Burn uses an unprotected C:\Windows\Temp directory to copy binaries and run them from there. This directory is not entirely protected against low privilege users.&lt;/p&gt;
&lt;p&gt;### Details
When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points to an insecure directory C:\Windows\Temp to drop and load multiple binaries. Standard users can hijack the binary before it&amp;#39;s loaded in the application resulting in elevation of privileges.&lt;/p&gt;
&lt;p&gt;icacls c:\windows\temp&lt;/p&gt;
&lt;p&gt;**BUILTIN\Users:(CI)(S,WD,AD,X)** 
BUILTIN\Administrators:(F)
BUILTIN\Administrators:(OI)(CI)(IO)(F)
NT AUTHORITY\SYSTEM:(F)
NT AUTHORITY\SYSTEM:(OI)(CI)(IO)(F)
 CREATOR OWNER:(OI)(CI)(IO)(F)
                
Built in users(non-administrators) have special permissions to this folder and can create files and write to this directory. While they do not have explicit read permissions, there is a way they can monitor the changes to this directory using ReadDirectoryChangesW API and thus figure out randomized folder names created inside this directory as wel&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;PoC works against the against visual studio enterprise with update 3 [installer ](https://myvs.download.prss.microsoft.com/dbazure/en_visual_studio_enterprise_2015_with_update_3_x86_x64_dvd_8923288.iso?t=8132cd54-4b83-4478-8b73-fd9eb93437bf&amp;amp;P1=1709239640&amp;amp;P2=601&amp;amp;P3=2&amp;amp;P4=iorgKPv%2bG8n2NANTPUVoB92rr8t3W4XM594%2f9BtQQJrYrr8SwxGDxV%2fj%2f2F6Ulto0bXrIaFoZUr4yV37YAsOZVpM29IMtQEO0673AbDVuTe93qDb6wb7xdlpZSse0LZURUwwIFw5cwHQS2ZtvkunXE0osgXtEBT2IzVbPwVH39%…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rf39-3f98-xr7r</guid>
    </item>
    <item>
      <title>gsd-2024-29187</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-29187</link>
      <description>gsd-2024-29187</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-29187</guid>
    </item>
    <item>
      <title>VDE-2024-021 — WAGO: Vulnerability in WAGO Navigator</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-021</link>
      <description>&lt;p&gt;The WAGO Navigator versions 1.0.1 and 1.0 are vulnerable due to the use of the WiX toolset version 3.11.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The WAGO Navigator versions 1.0.1 and 1.0 are vulnerable due to the use of the WiX toolset version 3.11.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-021</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1338 — Microsoft Visual Studio: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1338</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio 2017, Microsoft Visual Studio 2019 und Microsoft Visual Studio 2022 ausnutzen, um seine Privilegien zu erhöhen oder beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio 2017, Microsoft Visual Studio 2019 und Microsoft Visual Studio 2022 ausnutzen, um seine Privilegien zu erhöhen oder beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1338</guid>
    </item>
  </channel>
</rss>
