PT-2025-16929 · Nullsoft+1 · Nsis+1
Sandro Poppi
·
Published
2025-04-16
·
Updated
2026-04-09
·
CVE-2025-43715
CVSS v3.1
8.1
High
| Vector | AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nullsoft Scriptable Install System (NSIS) versions prior to 3.11
Description
The issue allows local users to escalate privileges to SYSTEM during an installation. This occurs because the temporary plugins directory is created under %WINDIR%temp and unprivileged users can place a crafted executable file by winning a race condition. The EW CREATEDIR does not always set the CreateRestrictedDirectory error flag.
Recommendations
For versions prior to 3.11, update to version 3.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary plugins directory under %WINDIR%temp to minimize the risk of exploitation.
Fix
LPE
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Nsis