CVE-2017-20051Medium· 6.3▾ TwilightPoC availableA vulnerability was detected in InnoSetup Installer 5.5.9. This affects an unknown part. The manipulation results in uncontrolled search path. The attack can be executed remotely. The exploit is now public and may be used. This is a malf…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 34.7 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
A vulnerability was detected in InnoSetup Installer 5.5.9. This affects an unknown part. The manipulation results in uncontrolled search path. The attack can be executed remotely. The exploit is now public and may be used. This is a malformed-PE / self-extracting-installer defect report that the vendor never acknowledged.
inno_setupRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-3433High· 7.8A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack
CVE-2020-3153Medium· 6.5A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges
CVE-2026-18718High· 7.0Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path
CVE-2026-6958High· 7.8Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a m…
CVE-2026-69328High· 7.8Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-78680High· 7.8NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary …