216.73.217.22

CVE-2025-43715

· Published 17/04/2025 03:15 · Modified 17/04/2025 20:21

Labels: CVE-2025-43715 2025-04-17CVE-2025-43715CWE-754[email protected]

Essential information

Published
17/04/2025 03:15
Modified
17/04/2025 20:21
Author
Creator
CVSS
8.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
nullsoft / nsis cpe:2.3:a:nullsoft:nsis:<3.11:*:*:*:*:*:*:*

References