CVE-2025-43715Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-09: 1Technical Details · 2026-04-09: 104-09
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • AmberWolf@AmberWolfSec
    Disclosure

    Two NSIS CVEs in play: CVE-2023-37378 - weak ACLs on the uninstaller temp directory, exploitable via DotLocal redirection or NTFS junction swaps CVE-2025-43715 - race condition in plugin directory creation, letting an attacker hijack $PLUGINSDIR before it's locked down

    Post summary

    The text provides technical details about two NSIS vulnerabilities but lacks evidence of active exploitation, PoC, patch, or deprecation.

    10000503
    436 followersView on X

Explore more