Privilege Escalation Vulnerability in Nullsoft Scriptable Install System by Nullsoft
CVE-2025-43715
What is CVE-2025-43715?
A vulnerability in the Nullsoft Scriptable Install System (NSIS) allows local users on Windows to escalate their privileges to SYSTEM during installation processes. This occurs due to a race condition in the management of the temporary plugins directory, which is improperly created under %WINDIR%\temp. Unprivileged users may exploit this by adding a malicious executable. The underlying issue arises as the EW_CREATEDIR command does not consistently trigger the CreateRestrictedDirectory error flag, leading to potential unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Nullsoft Scriptable Install System 0 < 3.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
