Nullsoft Scriptable Install System vulnerabilities
5 known vulnerabilities affecting nullsoft/nullsoft_scriptable_install_system.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-42171P3HIGHCVSS 7.8≥ 3.06.1, < 3.122026-04-24
CVE-2026-42171 [HIGH] CWE-427 CVE-2026-42171: NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp director
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).
nvd
CVE-2025-43715P3HIGHCVSS 8.1fixed in 3.112025-04-17
CVE-2025-43715 [HIGH] CWE-754 CVE-2025-43715: Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate priv
Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set
nvd
CVE-2015-9268P4HIGHCVSS 7.8fixed in 2.492018-10-01
CVE-2015-9268 [HIGH] CWE-20 CVE-2015-9268: Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dl
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
nvd
CVE-2023-37378P4MEDIUMCVSS 5.3≤ 3.092023-07-03
CVE-2023-37378 [MEDIUM] CVE-2023-37378: Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller d
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
nvd
CVE-2015-9267P4MEDIUMCVSS 5.5fixed in 2.492018-10-01
CVE-2015-9267 [MEDIUM] CWE-269 CVE-2015-9267: Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unp
Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.
nvd