CVE-2026-42171
EUVD-2026-2563724.04.2026, 22:16
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nullsoft | nullsoft_scriptable_install_system | 3.06.1 ≤ 𝑥 < 3.12 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration
References