CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
Percentile
47.3%
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access
control for an uninstaller directory.
sf.net/p/nsis/bugs/1296
github.com/kichik/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967
github.com/kichik/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967 (v309)
github.com/kichik/nsis/commit/409b5841479c44fbf33a6ba97c1146e46f965467
github.com/kichik/nsis/commit/409b5841479c44fbf33a6ba97c1146e46f965467 (v309)
github.com/kichik/nsis/commit/c40cf78994e74a1a3a381a850c996b251e3277c0
github.com/kichik/nsis/commit/c40cf78994e74a1a3a381a850c996b251e3277c0 (v309)
launchpad.net/bugs/cve/CVE-2023-37378
nsis.sourceforge.io/Docs/AppendixF.html#v3.09
nvd.nist.gov/vuln/detail/CVE-2023-37378
security-tracker.debian.org/tracker/CVE-2023-37378
sourceforge.net/p/nsis/news/2023/07/nsis-309-released/
www.cve.org/CVERecord?id=CVE-2023-37378