Логотип exploitDog
bind:CVE-2025-43715
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43715

Количество 5

Количество 5

ubuntu логотип

CVE-2025-43715

8 месяцев назад

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2025-43715

8 месяцев назад

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2025-43715

8 месяцев назад

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allow ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-g9m2-7jc6-pmvf

8 месяцев назад

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2025-10968

8 месяцев назад

Уязвимость системы разработки установочных программ Nullsoft Scriptable Install System, связанная с недостаточной проверкой необычных или исключительных состояний, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-43715

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-43715

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-43715

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allow ...

CVSS3: 8.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-g9m2-7jc6-pmvf

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

CVSS3: 8.1
0%
Низкий
8 месяцев назад
fstec логотип
BDU:2025-10968

Уязвимость системы разработки установочных программ Nullsoft Scriptable Install System, связанная с недостаточной проверкой необычных или исключительных состояний, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.1
0%
Низкий
8 месяцев назад

Уязвимостей на страницу