CVE-2023-37378: Medium severity Nullsoft Nullsoft Scriptable Install System vulnerability
Published Jul 3, 2023
·Updated
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
Affected Software
1 affected component
Nullsoft Nullsoft Scriptable Install System<=3.09
Event History
Jul 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37378?
CVE-2023-37378 has a medium severity rating due to mishandling of access control.
2
How do I fix CVE-2023-37378?
To fix CVE-2023-37378, upgrade to Nullsoft Scriptable Install System version 3.09 or later.
3
What type of vulnerability is CVE-2023-37378?
CVE-2023-37378 is an access control vulnerability affecting the uninstaller directory.
4
Which versions of NSIS are affected by CVE-2023-37378?
NSIS versions before 3.09 are affected by CVE-2023-37378.
5
Can CVE-2023-37378 be exploited remotely?
CVE-2023-37378 requires local access to exploit, limiting its remote exploitation potential.