PT-2026-35088 · Nullsoft+2 · Nullsoft Scriptable Install System+1

Published

2026-04-24

·

Updated

2026-05-18

·

CVE-2026-42171

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NSIS (Nullsoft Scriptable Install System) versions 3.06.1 through 3.11
Description When executing as SYSTEM, the software sometimes uses the Low Integrity Level (Low IL) temporary directory. This allows local attackers to gain elevated privileges if they can cause the my GetTempFileName() function to return 0.
Recommendations Update to version 3.12.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2026-42171

Affected Products

Nullsoft Scriptable Install System
Nsis