漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
对因果或异常条件的不恰当检查
Vulnerability Title
Nullsoft Scriptable Install System 安全漏洞
Vulnerability Description
Nullsoft Scriptable Install System是Nullsoft团队的一个专业的开源系统,用于创建 Windows 安装程序。 Nullsoft Scriptable Install System 3.11之前版本存在安全漏洞,该漏洞源于临时插件目录创建不当,可能导致本地用户权限提升至SYSTEM。
CVSS Information
N/A
Vulnerability Type
N/A