Impact
SiYuan Windows installers before version 3.8.1 contain an uncontrolled search path issue in the NSIS installer. During the pre‑initialization stage the installer executes privileged system utilities such as TASKKILL by name, and NSIS resolves the target executable by searching the installer's launch directory before System32. If a malicious file with the same name is placed in that directory, it will be launched with elevated privileges when the installer runs for all‑users. This flaw allows a local attacker to obtain elevated privileges on the machine, classified as a CWE‑427 vulnerability and scored with a CVSS of 7, which represents a moderate‑to‑high severity local privilege escalation.
Affected Systems
The affected product is the SiYuan note‑taking application from the vendor siyuan‑note, released under the product name Siyuan. All Windows installer packages from version 2.0.14 through, but excluding, version 3.8.1 are vulnerable. Users of these releases who run the installer from directories that an attacker can write to are exposed to this risk.
Risk and Exploitability
The exploitation requires only that the installer be run in a location that contains a malicious executable renamed to match a system utility, and that the installer be executed with elevated privileges. Because the attacker does not need remote access, the risk is primarily local. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 7 indicates a potentially serious compromise. The risk is higher in environments where software is installed from untrusted or shared directories. Based on the description, it is inferred that the attacker must be able to place the file in the installation directory, so networks or remote attacks are not required.
OpenCVE Enrichment