7.8
CVE-2025-15595
- EPSS 0.09%
- Veröffentlicht 03.03.2026 06:13:07
- Zuletzt bearbeitet 13.03.2026 17:55:35
- Quelle db4dfee8-a97e-4877-bfae-eba6d1
- CVE-Watchlists
- Unerledigt
Privilege escalation via dll hijacking in Inno Setup
Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jrsoftware ≫ Inno Setup Version <= 6.2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.007 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| db4dfee8-a97e-4877-bfae-eba6d14a2166 | 5.7 | 0 | 0 |
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:Clear
|
CWE-1390 Weak Authentication
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
https://jrsoftware.org/files/is6.2-whatsnew.htm