You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2024-29187
About this tag
CVE-2024-29187 is a security vulnerability affecting WiX Burn-based installer bundles, commonly used with Visual Studio. Discovered and patched by Microsoft in August 2024, the flaw enables binary hijacking when bundles run with SYSTEM privileges. Microsoft released security updates for Visual Studio on August 18, 2024 to address this risk. Discussions on WindowsForum cover the vulnerability's impact, mitigation steps, and the importance of applying the updates promptly to protect systems from potential exploitation.
Overview
On August 13, 2024, Microsoft announced a significant security vulnerability identified as CVE-2024-29187. This weakness affects WiX Burn-based bundles, which are often utilized in the creation and deployment of installer packages. The vulnerability allows for binary hijacking when...