In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade PanelSwWix4.Sdk
to version 5.0.0-psw-wix.0265-49 or higher.
Affected versions of this package are vulnerable to Untrusted Search Path due to the use of an unprotected C:\Windows\Temp
directory to copy and execute binaries. When executed as SYSTEM user, the process uses GetTempPathW
which points to this insecure directory, allowing standard users to hijack the binary before it's loaded, leading to elevation of privileges.
Note:
This is only exploitable if the attacker has the ability to create or write to files in the C:\Windows\Temp
directory and can monitor directory changes to figure out randomized folder names created inside this directory.