Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 1 min 99 bronnen 3 kritiek 34 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2026-42171

HIGH · 7.8 CVSS Gepubliceerd: CWE-427

Beschrijving

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).

Vendors

Nullsoft

Affected products

Nullsoft Scriptable Install System

References