CVE-2015-9268
published 2018-10-01CVE-2015-9268: Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in…
PriorityP432high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.54%
72.4th percentile
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nsis | < nsis 2.50-1 (bookworm) | nsis 2.50-1 (bookworm) |
| nullsoft | nullsoft_scriptable_install_system | < 2.49 | 2.49 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation SIS Workstation and ISaGRAF Workbench
cisa_ics·2023-11-14·CVSS 7.8
[HIGH] Rockwell Automation SIS Workstation and ISaGRAF Workbench
ICS Advisory
##
Rockwell Automation SIS Workstation and ISaGRAF Workbench
Release DateNovember 14, 2023
Alert CodeICSA-23-318-02
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Rockwell Automation
- Equipment: SIS Workstation and ISaGRAF Workbench
- Vulnerability: Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow unprivileged local users to overwrite files replacing them with malicious programs.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Rockwell Automation reports the following versions of SIS Workstation and ISaGRAF Workbench Code are affected:
- Safety Instrumented System Workstation: v1.2 up to but not including v2.00
- ISaGRAF Workbench: v6.
Debian
CVE-2015-9268: nsis - Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linkin...
vendor_debian·2015·CVSS 7.8
CVE-2015-9268 [HIGH] CVE-2015-9268: nsis - Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linkin...
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
Scope: local
bookworm: resolved (fixed in 2.50-1)
bullseye: resolved (fixed in 2.50-1)
forky: resolved (fixed in 2.50-1)
sid: resolved (fixed in 2.50-1)
trixie: resolved (fixed in 2.50-1)
GHSA
GHSA-xcj3-538v-c35r: Nullsoft Scriptable Install System (NSIS) before 2
ghsa_unreviewed·2022-05-13
CVE-2015-9268 [HIGH] CWE-20 GHSA-xcj3-538v-c35r: Nullsoft Scriptable Install System (NSIS) before 2
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
OSV
CVE-2015-9268: Nullsoft Scriptable Install System (NSIS) before 2
osv·2018-10-01·CVSS 7.8
CVE-2015-9268 [HIGH] CVE-2015-9268: Nullsoft Scriptable Install System (NSIS) before 2
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-10-01
Published