CVE-2026-42171

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).
Configurations

Configuration 1 (hide)

cpe:2.3:a:nullsoft:nullsoft_scriptable_install_system:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-24 22:16

Updated : 2026-06-17 10:47


NVD link : CVE-2026-42171

Mitre link : CVE-2026-42171

CVE.ORG link : CVE-2026-42171


JSON object : View

Products Affected

nullsoft

  • nullsoft_scriptable_install_system
CWE
CWE-427

Uncontrolled Search Path Element