{"id":"CVE-2024-29188","summary":"Malicious directory junction can cause WiX RemoveFoldersEx to possibly delete elevated files","details":"WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx` functionality could allow a standard user to delete protected directories. `RemoveFolderEx` deletes an entire directory tree during installation or uninstallation. It does so by recursing every subdirectory starting at a specified directory and adding each subdirectory to the list of directories Windows Installer should delete. If the setup author instructed `RemoveFolderEx` to delete a per-user folder from a per-machine installer, an attacker could create a directory junction in that per-user folder pointing to a per-machine, protected directory. Windows Installer, when executing the per-machine installer after approval by an administrator, would delete the target of the directory junction. This vulnerability is fixed in 3.14.1 and 4.0.5.","aliases":["GHSA-jx4p-m4wm-vvjg"],"modified":"2026-08-18T16:54:49.041634Z","published":"2024-03-24T19:46:25.875Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-59"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29188.json","unresolved_ranges":[{"extracted_events":[{"fixed":"3.14.1"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29188.json"},{"type":"ADVISORY","url":"https://github.com/wixtoolset/issues/security/advisories/GHSA-jx4p-m4wm-vvjg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29188"},{"type":"FIX","url":"https://github.com/wixtoolset/wix/commit/2e5960b575881567a8807e6b8b9c513138b19742"},{"type":"FIX","url":"https://github.com/wixtoolset/wix3/commit/93eeb5f6835776694021f66d4226c262c67d487a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wixtoolset/wix","events":[{"introduced":"8c757c0f67f26f21c6bcbbfb81b7ea8b91c35fe4"},{"fixed":"2e5960b575881567a8807e6b8b9c513138b19742"}],"database_specific":{"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.0.5"}],"source":["AFFECTED_FIELD","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/wixtoolset/wix3","events":[{"introduced":"0"},{"fixed":"93eeb5f6835776694021f66d4226c262c67d487a"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v4.0.4","v4.0.3","v4.0.2","v4.0.1","v4.0.0","wix314rtm","wix311rtm","wix3102rtm","wix3101rtm","wix310rtm","wix39rtm","wix38rtm"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-29188.json","vanir_signatures_modified":"2026-08-18T16:54:49Z","vanir_signatures":[{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["12167210011196546278955702443042459595","212815768888917157328275995063511215543","262360907396483902333948926594438991859","123568908231580348393599730054889329806","248970759541077859269682561881081196538","79948356566962686282965687718817036977","206692363494623044553551604119053240060","310907125740997366349245302936256045271"]},"id":"CVE-2024-29188-3c9d8a4e","signature_type":"Line","signature_version":"v1","source":"https://github.com/wixtoolset/wix/commit/2e5960b575881567a8807e6b8b9c513138b19742","target":{"file":"src/ext/Util/ca/RemoveFoldersEx.cpp"}},{"source":"https://github.com/wixtoolset/wix3/commit/93eeb5f6835776694021f66d4226c262c67d487a","target":{"file":"src/ext/ca/wixca/dll/RemoveFoldersEx.cpp"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["330081163568180098271931014562006408202","67559101698235371247063683629216861769","273739843084938211800361670883289621713","148327883292450560052301475267621766056","98974881564231501315083202825516671299","327061149520605942937828174320452813060","184074362942257707176474370884531980034","105330465127032992712314238713430570689"]},"id":"CVE-2024-29188-4b4af6af","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/wixtoolset/wix3/commit/93eeb5f6835776694021f66d4226c262c67d487a","target":{"file":"src/DTF/Tools/SfxCA/SfxUtil.cpp","function":"DeleteDirectory"},"deprecated":false,"digest":{"function_hash":"42402641038884878137330073238233142554","length":769},"id":"CVE-2024-29188-551cbb09","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/wixtoolset/wix/commit/2e5960b575881567a8807e6b8b9c513138b19742","target":{"file":"src/dtf/SfxCA/SfxUtil.cpp"},"deprecated":false,"digest":{"line_hashes":["315398171143457755832727327284327518902","57433646776359551242018896393001631255","153390547766836153243384045211714248960","204722630655963928047106757089072424351"],"threshold":0.9},"id":"CVE-2024-29188-7a292542"},{"signature_version":"v1","source":"https://github.com/wixtoolset/wix3/commit/93eeb5f6835776694021f66d4226c262c67d487a","target":{"function":"RecursePath","file":"src/ext/ca/wixca/dll/RemoveFoldersEx.cpp"},"deprecated":false,"digest":{"function_hash":"199099740742973738733939807511981395287","length":2465},"id":"CVE-2024-29188-aa87b978","signature_type":"Function"},{"target":{"file":"src/dtf/SfxCA/SfxUtil.cpp","function":"DeleteDirectory"},"deprecated":false,"digest":{"function_hash":"42402641038884878137330073238233142554","length":769},"id":"CVE-2024-29188-ec4e528f","signature_type":"Function","signature_version":"v1","source":"https://github.com/wixtoolset/wix/commit/2e5960b575881567a8807e6b8b9c513138b19742"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/wixtoolset/wix3/commit/93eeb5f6835776694021f66d4226c262c67d487a","target":{"file":"src/DTF/Tools/SfxCA/SfxUtil.cpp"},"deprecated":false,"digest":{"line_hashes":["315398171143457755832727327284327518902","57433646776359551242018896393001631255","153390547766836153243384045211714248960","204722630655963928047106757089072424351"],"threshold":0.9},"id":"CVE-2024-29188-ef5ee984"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/wixtoolset/wix/commit/2e5960b575881567a8807e6b8b9c513138b19742","target":{"file":"src/ext/Util/ca/RemoveFoldersEx.cpp","function":"RecursePath"},"deprecated":false,"digest":{"function_hash":"125636100461973275335596632368738494896","length":2819},"id":"CVE-2024-29188-f7e4fe74"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H"}]}