Nssm-2.24 Privilege Escalation ((new)) -
NSSM 2.24 – Weak Default Service Permissions Allow Local Privilege Escalation
If you must use NSSM, migrate to version 2.24 . Better yet, use a maintained alternative like WinSW with XML configuration files that support integrity checks. nssm-2.24 privilege escalation
In a locked-down environment, the user cannot start the service themselves. However, an attacker can simply wait for the server to reboot (or trigger a crash/reboot via another vector), at which point the service starts automatically. NSSM 2
: Misconfigured permissions on nssm.exe allowed local privilege escalation. Mitigation and Defense nssm-2.24 privilege escalation