Логотип exploitDog
bind:CVE-2025-43715
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43715

Количество 5

Количество 5

ubuntu логотип

CVE-2025-43715

10 месяцев назад

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2025-43715

10 месяцев назад

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2025-43715

10 месяцев назад

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allow ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-g9m2-7jc6-pmvf

10 месяцев назад

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2025-10968

10 месяцев назад

Уязвимость системы разработки установочных программ Nullsoft Scriptable Install System, связанная с недостаточной проверкой необычных или исключительных состояний, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-43715

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-43715

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-43715

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allow ...

CVSS3: 8.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-g9m2-7jc6-pmvf

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
fstec логотип
BDU:2025-10968

Уязвимость системы разработки установочных программ Nullsoft Scriptable Install System, связанная с недостаточной проверкой необычных или исключительных состояний, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.1
0%
Низкий
10 месяцев назад

Уязвимостей на страницу