go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

A DLL Hijacking vulnerability exists in NSIS

TVN ID TVN201902131351336Iu
CVE ID CVE-2015-9268
Affected Products All installers created by NSIS 2.49 and before. Known affected products: TaishinBank.exe before 2.0.48 TaishinBankChromeEdge.exe before 2.0.48
Description There is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
Solution 1. Only download application from official web site. 2. If you use NSIS to create your own installer, please check version of NSIS and, if it is necessary, create a new installer.
Public Date 2019-04-15
Top