logo

NSIS Vulnerability: Temp Directory Risk

ID: bbc3d3f5-1ceb-5f0a-b751-4988f1824708

STIX ID: report--bbc3d3f5-1ceb-5f0a-b751-4988f1824708

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2026-05-15

Date Updated: 2026-07-31

...
...

NCC Group disclosed CVE-2023-37378 affecting NSIS ≤3.08 where the uninstaller creates and uses a temporary directory with overly permissive ACLs and insufficient cleanup, enabling a local attacker to poison the directory (or exploit a TOCTOU race and .local SxS loading) to achieve code execution at the privileges of the uninstaller (potentially SYSTEM). The advisory explains technical root causes, exploitation steps, PoC behavior, affected deployment scenarios, and notes that fixes removing permissive ACEs and hardening directory handling were released in NSIS 3.09.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.