CVE-2023-37378
published 2023-07-03CVE-2023-37378: Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.89%
55.9th percentile
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nsis | < nsis 3.08-3+deb12u1 (bookworm) | nsis 3.08-3+deb12u1 (bookworm) |
| nullsoft | nullsoft_scriptable_install_system | <= 3.09 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-37378: Nullsoft Scriptable Install System (NSIS) before 3
osv·2023-07-03·CVSS 5.3
CVE-2023-37378 [MEDIUM] CVE-2023-37378: Nullsoft Scriptable Install System (NSIS) before 3
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
GHSA
GHSA-5r79-3284-v2f8: Nullsoft Scriptable Install System (NSIS) before 3
ghsa_unreviewed·2023-07-03
CVE-2023-37378 GHSA-5r79-3284-v2f8: Nullsoft Scriptable Install System (NSIS) before 3
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
CISA ICS
Siemens Parasolid Installer
cisa_ics·2023-08-10·CVSS 5.3
[MEDIUM] Siemens Parasolid Installer
ICS Advisory
##
Siemens Parasolid Installer
Release DateAugust 10, 2023
Alert CodeICSA-23-222-02
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: Parasolid
- Vulnerability: Incorrect Permission Assignment for Critical Resource
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to misuse the vulnerability and escalate privileges.
## 3. TECH
Debian
CVE-2023-37378: nsis - Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control ...
vendor_debian·2023·CVSS 5.3
CVE-2023-37378 [MEDIUM] CVE-2023-37378: nsis - Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control ...
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
Scope: local
bookworm: resolved (fixed in 3.08-3+deb12u1)
bullseye: resolved (fixed in 3.06.1-1+deb11u1)
forky: resolved (fixed in 3.09-1)
sid: resolved (fixed in 3.09-1)
trixie: resolved (fixed in 3.09-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://sf.net/p/nsis/bugs/1296https://github.com/kichik/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967https://github.com/kichik/nsis/commit/409b5841479c44fbf33a6ba97c1146e46f965467https://github.com/kichik/nsis/commit/c40cf78994e74a1a3a381a850c996b251e3277c0https://lists.debian.org/debian-lts-announce/2023/07/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A65FBUMHLZ7GBV3VDKUB5EK3A7X2UUWK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OZPAAU57IA3NP6UOUXNBUQBAYK3JB2IM/https://nsis.sourceforge.io/Docs/AppendixF.html#v3.09https://sourceforge.net/p/nsis/news/2023/07/nsis-309-released/http://sf.net/p/nsis/bugs/1296https://github.com/kichik/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967https://github.com/kichik/nsis/commit/409b5841479c44fbf33a6ba97c1146e46f965467https://github.com/kichik/nsis/commit/c40cf78994e74a1a3a381a850c996b251e3277c0https://lists.debian.org/debian-lts-announce/2023/07/msg00005.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A65FBUMHLZ7GBV3VDKUB5EK3A7X2UUWK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OZPAAU57IA3NP6UOUXNBUQBAYK3JB2IM/https://nsis.sourceforge.io/Docs/AppendixF.html#v3.09https://sourceforge.net/p/nsis/news/2023/07/nsis-309-released/
2023-07-03
Published