Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-11066 | A vulnerability was found in InnoSetup Installer. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to uncontrolled search path. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
No reference.
Wed, 30 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-426 CWE-427 |
|
| CPEs | ||
| Vendors & Products |
Jrsoftware
Jrsoftware inno Setup |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Wed, 30 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in InnoSetup Installer 5.5.9. This affects an unknown part. The manipulation results in uncontrolled search path. The attack can be executed remotely. The exploit is now public and may be used. This is a malformed-PE / self-extracting-installer defect report that the vendor never acknowledged. | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The sole source documents PE-format conformance defects in innosetup-5.5.9.exe with no exploit, attack path, or untrusted search path condition (CWE-426/427), and the author states Windows loads these files normally; the record's remote/exploited claims are unsupported, as is the product maintainer's contention. |
| CPEs | ||
| Vendors & Products |
Innosetup
Innosetup installer |
|
| Metrics |
cvssV3_0
|
cvssV2_0
|
Tue, 29 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in InnoSetup Installer. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to uncontrolled search path. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | A vulnerability was detected in InnoSetup Installer 5.5.9. This affects an unknown part. The manipulation results in uncontrolled search path. The attack can be executed remotely. The exploit is now public and may be used. This is a malformed-PE / self-extracting-installer defect report that the vendor never acknowledged. |
| First Time appeared |
Innosetup
Innosetup installer |
|
| Weaknesses | CWE-426 | |
| CPEs | cpe:2.3:a:innosetup:installer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Innosetup
Innosetup installer |
|
| References |
| |
| Metrics |
cvssV2_0
|
cvssV3_0
|
Tue, 15 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
No data.
Status: REJECTED
Assigner: VulDB
Published:
Updated: 2026-09-30T17:36:21.043Z
Reserved: 2022-06-08T00:00:00.000Z
Link: CVE-2017-20051
Updated: 2024-08-05T21:45:25.374Z
Status : Modified
Published: 2022-06-16T07:15:07.053
Modified: 2026-09-29T06:16:56.450
Link: CVE-2017-20051
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD