{"id":"CVE-2026-42171","details":"NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).","modified":"2026-08-12T16:24:18.165495Z","published":"2026-04-24T21:20:35.525Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42171.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"3.06.1"},{"fixed":"3.12"}]},{"extracted_events":[{"introduced":"3.06.1"},{"fixed":"3.12"}],"source":"CPE_FIELD"},{"extracted_events":[{"introduced":"3.06.1"},{"fixed":"3.12"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre","cwe_ids":["CWE-427"]},"references":[{"type":"WEB","url":"https://github.com/NSIS-Dev/nsis/blob/7359413009afd4f0fff472d841fc2f2cc0e0a5f8/Source/exehead/util.c#L475-L484"},{"type":"WEB","url":"https://learn.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-gettempfilename"},{"type":"WEB","url":"https://nsis.sourceforge.io/Docs/AppendixF.html#v3.12-cl"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42171.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42171"},{"type":"FIX","url":"https://github.com/NSIS-Dev/nsis/commit/8e6f02205d5f22da6c7855dbfe59b2af667330ca"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nsis-dev/nsis","events":[{"introduced":"0"},{"fixed":"8e6f02205d5f22da6c7855dbfe59b2af667330ca"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v310","v309","v308","v307","v3061","v306","v305","v304","v303","v3021","v301","v30","v30rc2","v30rc1","v30b3","v30b2","v30b1","v30b0","v30a2","v30a1","v246","v245","v244","v243","v242","v241","v240","v239","v238","v237","v236","v235","v234","v233","v232","v231","v230","v229","v228","v227","v226","v225","v224","v223","v222","v221","v220","v219","v218","v217","v216","v215","v214","v213","v212","v211","v210","v208","v207","v207b0","v206","v205","v204","v203","v202","v201","v20","v20rc4","v20rc3","v20rc2","v20rc1","v20b4","v20b3","v20b2","v20b1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42171.json","vanir_signatures_modified":"2026-08-12T16:24:18Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/nsis-dev/nsis/commit/8e6f02205d5f22da6c7855dbfe59b2af667330ca","target":{"file":"Source/exehead/Main.c"},"deprecated":false,"digest":{"line_hashes":["40512102880778658124896654791287957887","55883558779287910620366181330180973683","171359798556859465837194176206311633652","293583849916359373402897435193249486875","136849797675635699153538033358179384812","314530838814439634160380642676912934191"],"threshold":0.9},"id":"CVE-2026-42171-336dc970","signature_type":"Line"},{"deprecated":false,"digest":{"function_hash":"192538915003321576615560420739527501523","length":7211},"id":"CVE-2026-42171-52b4332c","signature_type":"Function","signature_version":"v1","source":"https://github.com/nsis-dev/nsis/commit/8e6f02205d5f22da6c7855dbfe59b2af667330ca","target":{"file":"Source/exehead/Main.c","function":"NSISWinMainNOCRT"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}