Loading
Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.
Use CWE-269, Nullsoft vendor hub and Nullsoft Scriptable Install System product page to widen CVE-2015-9267 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2015-9268 and CVE-2023-37378 for nearby disclosures in the same product family.