CVE-2025-43715: Race Condition
Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EWCREATEDIR does not always set the CreateRestrictedDirectory error flag.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43715?
CVE-2025-43715 has a critical severity rating due to the potential for local privilege escalation to SYSTEM.
How do I fix CVE-2025-43715?
To mitigate CVE-2025-43715, upgrade to Nullsoft Scriptable Install System version 3.11 or later.
Who is affected by CVE-2025-43715?
CVE-2025-43715 affects all local users of Nullsoft Installer versions prior to 3.11 on Windows.
What is the nature of the vulnerability in CVE-2025-43715?
CVE-2025-43715 involves a race condition that allows unprivileged users to execute crafted files in a temporary plugins directory.
Can CVE-2025-43715 be exploited remotely?
CVE-2025-43715 cannot be exploited remotely as it requires local user access to the affected system.