CVE-2018-6947 describes a privilege escalation vulnerability in the nxfuse component of the Open Source DokanFS library, as shipped with NoMachine 6.0.66_2 and earlier. This flaw allows a local, low-privileged user to elevate privileges on Windows 7 and cause a denial of service on Windows 8 and 10. With a CVSS score of 7.8 (High), the vulnerability has a low attack complexity and can lead to high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, public exploit code is available on ExploitDB, and there has been some community discussion, including a Reddit post detailing the path to code execution.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.66_2CPE matchmatch criteria | cpe:2.3:a:nomachine:nomachine:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.