Are downloads subject to MITM attacks?

I am currently seeking help in another thread for a problem with an ISO file, possibly related to mkisofs.exe, and while I was researching I noticed that WOU connects to its website to get the latest version of mkisofs.exe. Do any of these supporting programs needed by WOU have a digital signature or if not how is the client verifying them as legitimate in order to prevent against a Man-In-The-Middle (MITM) attack? Thanks