CVE-2023-37378
MEDIUMNullsoft Scriptable Install System <3.09 - Privilege Escalation
Title source: llmDescription
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
References (10)
Core 10
Core References
Issue Tracking, Permissions Required
http://sf.net/p/nsis/bugs/1296
Release Notes
https://nsis.sourceforge.io/Docs/AppendixF.html#v3.09
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2023/07/msg00005.html
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OZPAAU57IA3NP6UOUXNBUQBAYK3JB2IM/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A65FBUMHLZ7GBV3VDKUB5EK3A7X2UUWK/
Scores
CVSS v3
5.3
EPSS
0.0036
EPSS Percentile
58.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
Status
published
Products (1)
nullsoft/nullsoft_scriptable_install_system
< 3.09
Published
Jul 03, 2023
Tracked Since
Feb 18, 2026