CVE-2023-37378Disclosure(nullsoft / nullsoft_scriptable_install_system)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nullsoft_scriptable_install_system

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
nullsoft_scriptable_install_system

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-09: 1Technical Details · 2026-04-09: 104-09
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • AmberWolf@AmberWolfSec
    Disclosure

    Two NSIS CVEs in play: CVE-2023-37378 - weak ACLs on the uninstaller temp directory, exploitable via DotLocal redirection or NTFS junction swaps CVE-2025-43715 - race condition in plugin directory creation, letting an attacker hijack $PLUGINSDIR before it's locked down

    Post summary

    The message discloses technical details of two NSIS vulnerabilities—weak ACLs exploitable via redirection or junction swaps, and a race condition that permits $PLUGINSDIR hijacking—without mentioning PoC, exploit tools, active exploitation, or patches.

    10000503
    436 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnullsoftnullsoft_scriptable_install_system---

Explore more