Issue #22064 has been updated by Rob Reynolds.
The WiX installer currently creates the facts.d folder without setting any explicit permissions. The installer should only allow Write permissions to Administrators and SYSTEM, and read permissions to Users. Other installers do not create the folder, and we are investigating whether we should create the folder or not. ---------------------------------------- Bug #22064: Potential Local Escalation issue with Facts.d folder for executable facts on Windows https://projects.puppetlabs.com/issues/22064#change-95994 * Author: Rob Reynolds * Status: Accepted * Priority: High * Assignee: Rob Reynolds * Category: windows * Target version: 1.7.x * Keywords: windows * Branch: * Affected Facter version: ---------------------------------------- When we enable executable facts, we need to ensure the facts.d folder is locked down by the installer. -- You have received this notification because you have either subscribed to it, or are involved in it. To change your notification preferences, please click here: http://projects.puppetlabs.com/my/account -- You received this message because you are subscribed to the Google Groups "Puppet Bugs" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. Visit this group at http://groups.google.com/group/puppet-bugs. For more options, visit https://groups.google.com/groups/opt_out.
