CVE-2018-6947

An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of service for Windows 8 and 10.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nomachine:nomachine:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:11

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/44167/ - Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/44167/ - Third Party Advisory, VDB Entry
References () https://www.exploit-db.com/exploits/44168/ - Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/44168/ - Third Party Advisory, VDB Entry
References () https://www.fidusinfosec.com/nomachine-road-code-execution-without-fuzzing-cve-2018-6947/ - Third Party Advisory () https://www.fidusinfosec.com/nomachine-road-code-execution-without-fuzzing-cve-2018-6947/ - Third Party Advisory
References () https://www.nomachine.com/SU02P00194 - Vendor Advisory () https://www.nomachine.com/SU02P00194 - Vendor Advisory
References () https://www.nomachine.com/SU02P00195 - Vendor Advisory () https://www.nomachine.com/SU02P00195 - Vendor Advisory
References () https://www.nomachine.com/TR02P08408 - Vendor Advisory () https://www.nomachine.com/TR02P08408 - Vendor Advisory

Information

Published : 2018-02-28 22:29

Updated : 2024-11-21 04:11


NVD link : CVE-2018-6947

Mitre link : CVE-2018-6947

CVE.ORG link : CVE-2018-6947


JSON object : View

Products Affected

microsoft

  • windows_10
  • windows_8
  • windows_7

nomachine

  • nomachine
CWE
CWE-665

Improper Initialization