NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 24 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references). | |
| First Time appeared |
Nullsoft
Nullsoft nullsoft Scriptable Install System |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:nullsoft:nullsoft_scriptable_install_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nullsoft
Nullsoft nullsoft Scriptable Install System |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-24T21:21:39.224Z
Reserved: 2026-04-24T21:20:35.145Z
Link: CVE-2026-42171
No data.
Status : Received
Published: 2026-04-24T22:16:01.540
Modified: 2026-04-24T22:16:01.540
Link: CVE-2026-42171
No data.
OpenCVE Enrichment
No data.
Weaknesses