
Cloud Vulnerability DB
A community-led vulnerabilities database
Nullsoft Scriptable Install System (NSIS) before version 3.11 contains a privilege escalation vulnerability identified as CVE-2025-43715. The vulnerability was discovered in early 2025 and affects Windows systems. The issue allows local users to escalate privileges to SYSTEM during an installation process due to improper handling of temporary plugin directories (NVD, NSIS Docs).
The vulnerability stems from a race condition in the creation of temporary plugin directories under %WINDIR%\temp. The core issue lies in the EW_CREATEDIR functionality, which fails to consistently set the CreateRestrictedDirectory error flag. This implementation flaw allows unprivileged users to place crafted executable files in the directory by winning a race condition during the installation process (NSIS Bug). The vulnerability has been assigned a CVSS v3.1 base score of 8.1 (HIGH) with the vector string CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H (NVD).
The successful exploitation of this vulnerability allows local users to escalate their privileges to SYSTEM level on affected Windows systems. This means an attacker could gain the highest level of system privileges, potentially leading to complete system compromise (NVD).
The vulnerability requires local access and involves winning a race condition during the installation process. The attacker needs to time the placement of a crafted executable file in the temporary plugins directory precisely when an installer with SYSTEM privileges is running (NVD).
The vulnerability has been fixed in NSIS version 3.11. The update implements proper error handling for the CreateRestrictedDirectory flag in the EW_CREATEDIR functionality. Users and organizations are strongly advised to upgrade to version 3.11 or later to mitigate this security risk (NSIS Docs).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."