Nullsoft

    Dashboard / Vendors

    Products: 4
    Vulnerabilities: 78
    Known Exploited: 0
    28
    Critical Level Threats
    25
    High Level Threats
    19
    Medium Level Threats
    6
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-42171

    Low IL Temp Directory Path Exposure Allows Local Privilege Escalation

    Last Modified: Apr 28, 2026
    Published: Apr 24, 2026

    CVE-2025-43715

    Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.

    Last Modified: Apr 15, 2026
    Published: Apr 17, 2025

    CVE-2023-37378

    Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.

    Last Modified: Nov 21, 2024
    Published: Jul 03, 2023

    CVE-2015-9268

    Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.

    Last Modified: Nov 21, 2024
    Published: Oct 01, 2018

    CVE-2015-9267

    Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.

    Last Modified: Nov 21, 2024
    Published: Oct 01, 2018
    Items Per Page
    Nullsoft Vulnerabilities & Security CVEs | CVE-DB