Description
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 25 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references). | |
| First Time appeared |
Nullsoft
Nullsoft nullsoft Scriptable Install System |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:nullsoft:nullsoft_scriptable_install_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nullsoft
Nullsoft nullsoft Scriptable Install System |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-25T01:56:37.358Z
Reserved: 2026-04-24T21:20:35.145Z
Link: CVE-2026-42171
Updated: 2026-04-25T01:56:33.733Z
Status : Received
Published: 2026-04-24T22:16:01.540
Modified: 2026-04-24T22:16:01.540
Link: CVE-2026-42171
No data.
OpenCVE Enrichment
No data.
Weaknesses