DEBIAN-CVE-2025-43715

Source
https://security-tracker.debian.org/tracker/CVE-2025-43715
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-43715.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2025-43715
Upstream
Published
2025-04-17T03:15:16Z
Modified
2025-10-10T19:31:13.029255Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

References

Affected packages

Debian:11 / nsis

Package

Name
nsis
Purl
pkg:deb/debian/nsis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.06.1-1
3.06.1-1+deb11u1
3.07-1
3.08-1
3.08-2
3.08-3
3.09-1
3.09-2
3.09-3
3.09-4
3.10-1
3.10-2
3.11-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / nsis

Package

Name
nsis
Purl
pkg:deb/debian/nsis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.08-3
3.08-3+deb12u1
3.09-1
3.09-2
3.09-3
3.09-4
3.10-1
3.10-2
3.11-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / nsis

Package

Name
nsis
Purl
pkg:deb/debian/nsis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.11-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / nsis

Package

Name
nsis
Purl
pkg:deb/debian/nsis?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.11-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}