boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2017-20051

InnoSetup Installer uncontrolled search path
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0075   53.2     —
AFFECTED
  Product    Versions  Fixed
  Installer  5.5.9 –   —
TIMELINE
  Jun 8   Reserved by VulDB
  Jun 16  Published (CNA: VulDB)
  Sep 29  RESCORED — CVE-2017-20051 (InnoSetup Installer). CVSS 5.3 → 2.1 (NVD).
  Sep 30  REJECTED — CVE-2017-20051 (InnoSetup Installer). Record withdrawn by the CNA.
CWE-426, CWE-427 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Rejected

Description

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The sole source documents PE-format conformance defects in innosetup-5.5.9.exe with no exploit, attack path, or untrusted search path condition (CWE-426/427), and the author states Windows loads these files normally; the record's remote/exploited claims are unsupported, as is the product maintainer's contention.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
June 8, 2022ReservedReserved by VulDB
June 16, 2022PublishedPublished (CNA: VulDB)
September 29, 2026RESCOREDRESCORED — CVE-2017-20051 (InnoSetup Installer). CVSS 5.3 → 2.1 (NVD).
September 30, 2026REJECTEDREJECTED — CVE-2017-20051 (InnoSetup Installer). Record withdrawn by the CNA.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
InnoSetupInstaller—5.5.9—

Weaknesses

CWE-426 · CWE-427

References (5)

Related

Authoritative record: CVE-2017-20051 at cve.org

Vendors: innosetup

Weaknesses: CWE-426 · CWE-427

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2017-20051 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.