NSIS Vulnerability: Temp Directory Risk
ID: bbc3d3f5-1ceb-5f0a-b751-4988f1824708
STIX ID: report--bbc3d3f5-1ceb-5f0a-b751-4988f1824708
Feed Name: NCC Research
NCC Group disclosed CVE-2023-37378 affecting NSIS ≤3.08 where the uninstaller creates and uses a temporary directory with overly permissive ACLs and insufficient cleanup, enabling a local attacker to poison the directory (or exploit a TOCTOU race and .local SxS loading) to achieve code execution at the privileges of the uninstaller (potentially SYSTEM). The advisory explains technical root causes, exploitation steps, PoC behavior, affected deployment scenarios, and notes that fixes removing permissive ACEs and hardening directory handling were released in NSIS 3.09.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
