Back to CVE List

CVE-2026-42171

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.8 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Description

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-427
Source
NVD
Vendor
Nullsoft
Product
Nullsoft Scriptable Install System

External References

Discussion (0)

Add Comment

No comments yet. Be the first!