CVE-2018-17980 is a privilege escalation vulnerability affecting NoMachine versions before 5.3.27 and 6.x before 6.3.6. An attacker can gain elevated privileges by placing a malicious wintab32.dll file in the same directory as a .nxs file, leading to the execution of arbitrary code when the .nxs file is opened. This vulnerability has a CVSS v3 score of 7.8 (High), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog and with no observed active exploitation or significant community discussion, a public exploit (EDB-45611) exists, demonstrating its exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.3.27CPE matchmatch criteria | cpe:2.3:a:nomachine:nomachine:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.3.6CPE matchmatch criteria | cpe:2.3:a:nomachine:nomachine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.