← לוח פגיעויות

CVE-2026-42171

גבוהה 7.8

תיאור (מקור, אנגלית)

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).

מדדים

CVSS 3.1
7.8 (HIGH) מקור הציון: CNA CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-30/7/2026
CWE
CWE-427

מוצרים מושפעים

nullsoft: nullsoft scriptable install system

קישורים