{"api_version":"1","generated_at":"2026-07-24T17:19:07+00:00","cve":"CVE-2019-16511","urls":{"html":"https://cve.report/CVE-2019-16511","api":"https://cve.report/api/cve/CVE-2019-16511.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-16511","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-16511"},"summary":{"title":"CVE-2019-16511","description":"An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2. Microsoft.Deployment.Compression.Cab.dll and Microsoft.Deployment.Compression.Zip.dll allow directory traversal during CAB or ZIP archive extraction, because the full name of an archive file (even with a ../ sequence) is concatenated with the destination path.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-09-19 16:15:00","updated_at":"2019-11-04 18:15:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"https://www.firegiant.com/blog/2019/9/18/wix-v3.11.2-released/","name":"https://www.firegiant.com/blog/2019/9/18/wix-v3.11.2-released/","refsource":"MISC","tags":["Patch","Vendor Advisory"],"title":"WiX v3.11.2 released","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/wixtoolset/issues/issues/6075","name":"https://github.com/wixtoolset/issues/issues/6075","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"DTF vulnerable to \"Zip Slip\" · Issue #6075 · wixtoolset/issues · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/GitHubAssessments/CVE_Assessments_09_2019","name":"https://github.com/GitHubAssessments/CVE_Assessments_09_2019","refsource":"MISC","tags":[],"title":"GitHub - GitHubAssessments/CVE_Assessments_09_2019: Enpass","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://wixtoolset.org/development/wips/6075-dtf-zip-slip/","name":"https://wixtoolset.org/development/wips/6075-dtf-zip-slip/","refsource":"MISC","tags":["Third Party Advisory"],"title":"DTF vulnerable to \"Zip Slip\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-16511","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16511","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"16511","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"firegiant","cpe5":"wix_toolset","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"16511","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"firegiant","cpe5":"wix_toolset","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-16511","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2. Microsoft.Deployment.Compression.Cab.dll and Microsoft.Deployment.Compression.Zip.dll allow directory traversal during CAB or ZIP archive extraction, because the full name of an archive file (even with a ../ sequence) is concatenated with the destination path."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/wixtoolset/issues/issues/6075","refsource":"MISC","name":"https://github.com/wixtoolset/issues/issues/6075"},{"url":"https://wixtoolset.org/development/wips/6075-dtf-zip-slip/","refsource":"MISC","name":"https://wixtoolset.org/development/wips/6075-dtf-zip-slip/"},{"url":"https://www.firegiant.com/blog/2019/9/18/wix-v3.11.2-released/","refsource":"MISC","name":"https://www.firegiant.com/blog/2019/9/18/wix-v3.11.2-released/"},{"refsource":"MISC","name":"https://github.com/GitHubAssessments/CVE_Assessments_09_2019","url":"https://github.com/GitHubAssessments/CVE_Assessments_09_2019"}]}},"nvd":{"publishedDate":"2019-09-19 16:15:00","lastModifiedDate":"2019-11-04 18:15:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:firegiant:wix_toolset:*:*:*:*:*:*:*:*","versionEndExcluding":"3.11.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"16511","Ordinal":"156186","Title":"CVE-2019-16511","CVE":"CVE-2019-16511","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"16511","Ordinal":"1","NoteData":"An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2. Microsoft.Deployment.Compression.Cab.dll and Microsoft.Deployment.Compression.Zip.dll allow directory traversal during CAB or ZIP archive extraction, because the full name of an archive file (even with a ../ sequence) is concatenated with the destination path.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"16511","Ordinal":"2","NoteData":"2019-09-19","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"16511","Ordinal":"3","NoteData":"2019-11-04","Type":"Other","Title":"Modified"}]}}}