CVE-2026-42171
published 2026-04-24CVE-2026-42171: NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.21%
11.3th percentile
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nullsoft | nullsoft_scriptable_install_system | >= 3.06.1 < 3.12 | 3.12 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Nullsoft Scriptable Install System up to 3.11 my_GetTempFileName uncontrolled search path (EUVD-2026-25637)
vuldb·2026-04-25·CVSS 7.8
CVE-2026-42171 [HIGH] Nullsoft Scriptable Install System up to 3.11 my_GetTempFileName uncontrolled search path (EUVD-2026-25637)
A vulnerability marked as problematic has been reported in Nullsoft Scriptable Install System up to 3.11. Impacted is the function my_GetTempFileName. The manipulation leads to uncontrolled search path.
This vulnerability is listed as CVE-2026-42171. The attack must be carried out locally. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
GHSA-594m-24qw-wfmp: NSIS (Nullsoft Scriptable Install System) 3
ghsa_unreviewed·2026-04-25
CVE-2026-42171 [HIGH] CWE-427 GHSA-594m-24qw-wfmp: NSIS (Nullsoft Scriptable Install System) 3
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/NSIS-Dev/nsis/blob/7359413009afd4f0fff472d841fc2f2cc0e0a5f8/Source/exehead/util.c#L475-L484https://github.com/NSIS-Dev/nsis/commit/8e6f02205d5f22da6c7855dbfe59b2af667330cahttps://learn.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-gettempfilenamehttps://nsis.sourceforge.io/Docs/AppendixF.html#v3.12-cl
2026-04-24
Published