{"id":"CVE-2025-43715","details":"Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.","modified":"2026-01-27T04:20:12.337595Z","published":"2025-04-17T03:15:16Z","withdrawn":"2026-01-27T04:20:12.337595Z","references":[{"type":"WEB","url":"https://nsis.sourceforge.io/Docs/AppendixF.html#v3.11-rl"},{"type":"WEB","url":"https://sourceforge.net/p/nsis/bugs/1315/"}],"schema_version":"1.7.3"}