Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-42171

Опубликовано: 24 апр. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nullsoft:nullsoft_scriptable_install_system:*:*:*:*:*:*:*:*
Версия от 3.06.1 (включая) до 3.12 (исключая)

EPSS

Процентиль: 11%
0.0021
Низкий

7.8 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).

CVSS3: 7.8
debian
4 месяца назад

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes ...

CVSS3: 7.8
github
4 месяца назад

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).

EPSS

Процентиль: 11%
0.0021
Низкий

7.8 High

CVSS3

Дефекты

CWE-427