← Back to CVE search

CVE-2026-42171

NSIS

Description

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).

CVSS 7.8EPSS 0.21%Risk 0.79
View source
Published
2026-04-24 22:16:01
Affected versions
<3.12
Type
Core software
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H