3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether wix is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.3
CVE-2024-29187
WiX based installers are vulnerable to binary hijack when run as SYSTEM
HIGH 7.9
CVE-2024-29188
Malicious directory junction can cause WiX RemoveFoldersEx to possibly delete elevated files
HIGH 8.2
CVE-2024-24810
WiX Toolset's .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges
Browse more NuGet advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes