CVE-2025-15595 PUBLISHED

Privilege escalation via dll hijacking in Inno Setup

Assigner: NCSC-FI
Reserved: 27.02.2026 Published: 03.03.2026 Updated: 03.03.2026

Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/U:Clear
CVSS Score: 5.7

Product Status

Vendor mlsoft
Product Inno Setup
Versions Default: unaffected
  • affected from 0 to 6.2.1 (incl.)
  • Version 6.2.2 is unaffected

Solutions

Update to 6.2.2 or later

References

Problem Types

  • CWE-1390: Weak Authentication CWE

Impacts

  • CAPEC-233 Privilege Escalation