Security Advisory

CVE-2015-9267

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-10-01 08:00:00
Last updated 2024-08-06 08:43:42
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.