CVE-2026-42171

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).
Configurations

No configuration.

History

24 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-24 22:16

Updated : 2026-04-24 22:16


NVD link : CVE-2026-42171

Mitre link : CVE-2026-42171

CVE.ORG link : CVE-2026-42171


JSON object : View

Products Affected

No product.

CWE
CWE-427

Uncontrolled Search Path Element