PT-2026-83575 · Siyuan · Siyuan
CVSS v4.0
7.0
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
SiYuan Windows installer versions 2.0.14 through 3.8.0
Description
The NSIS installer contains an uncontrolled search path element issue where system executables, such as TASKKILL, are invoked by name instead of by an absolute path. The
nsExec::Exec function resolves these calls using a search path that prioritizes the installer's launch directory over System32. An attacker can place a malicious executable with the same name in the launch directory to achieve local privilege escalation, as the binary executes with an elevated token during an all-users installation. This occurs within the preInit hook of electron-builder before the license page is shown.Recommendations
Update to version 3.8.1 or later.
Exploit
Fix
LPE
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan