CVE-2017-20051

Executive Summary

CVE-2017-20051 was withdrawn by its CNA after investigation revealed no security impact. The reported PE‑format conformance defects in innosetup‑5.5.9.exe lacked an exploit, attack path, or untrusted search path condition (CWE‑426/427). Consequently, the CVE is not considered a vulnerability and is not listed in the CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: Unknown (Unknown) - Published: 2022-06-16T07:15:07.053 - Last Modified: 2026-09-30T18:17:17.283

Original Description: Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The sole source documents PE-format conformance defects in innosetup-5.5.9.exe with no exploit, attack path, or untrusted search path condition (CWE-426/427), and the author states Windows loads these files normally; the record's remote/exploited claims are unsupported, as is the product maintainer's contention.

"Great indeed is the sublimity of the Creative, to which all beings owe their beginning and which permeates all heaven."

— Lao Tzu
Source: NVD