Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Apr 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low IL Temp Directory Path Exposure Allows Local Privilege Escalation |
Sat, 25 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references). | |
| First Time appeared |
Nullsoft
Nullsoft nullsoft Scriptable Install System |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:nullsoft:nullsoft_scriptable_install_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nullsoft
Nullsoft nullsoft Scriptable Install System |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-25T19:33:05.317Z
Reserved: 2026-04-24T21:20:35.145Z
Link: CVE-2026-42171
Updated: 2026-04-25T01:56:33.733Z
Status : Awaiting Analysis
Published: 2026-04-24T22:16:01.540
Modified: 2026-04-27T18:57:20.293
Link: CVE-2026-42171
No data.
OpenCVE Enrichment
Updated: 2026-04-28T05:45:23Z