Description
Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.
Published: 2026-03-03
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to 6.2.2 or later

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 13 Mar 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Jrsoftware
Jrsoftware inno Setup
CPEs cpe:2.3:a:jrsoftware:inno_setup:*:*:*:*:*:*:*:*
Vendors & Products Jrsoftware
Jrsoftware inno Setup
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 04 Mar 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mlsoft
Mlsoft inno Setup
Vendors & Products Mlsoft
Mlsoft inno Setup

Tue, 03 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 03 Mar 2026 06:30:00 +0000

Type Values Removed Values Added
Description Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.
Title Privilege escalation via dll hijacking in Inno Setup
Weaknesses CWE-1390
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/U:Clear'}


Subscriptions

Jrsoftware Inno Setup
Mlsoft Inno Setup
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC-FI

Published:

Updated: 2026-03-03T14:37:26.000Z

Reserved: 2026-02-27T06:49:37.922Z

Link: CVE-2025-15595

cve-icon Vulnrichment

Updated: 2026-03-03T14:37:21.413Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-03T07:16:09.830

Modified: 2026-03-13T17:55:35.080

Link: CVE-2025-15595

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-04T14:54:31Z

Weaknesses