Privilege Escalation in NSIS by Nullsoft Scriptable Install System
CVE-2026-42171
7.8HIGH
What is CVE-2026-42171?
The Nullsoft Scriptable Install System (NSIS) prior to version 3.12 is affected by a privilege escalation vulnerability. When executed with SYSTEM privileges, NSIS can incorrectly use a Low Integrity Level temporary directory. This oversight allows local attackers to potentially gain higher privileges if they can manipulate the function my_GetTempFileName to return a value of 0, which can lead to unauthorized access and further exploitation. Users are recommended to upgrade to NSIS version 3.12 or later to mitigate this risk.
Affected Version(s)
Nullsoft Scriptable Install System 3.06.1 < 3.12
