CVE-2018-6384

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
31/01/2018
Last modified:
06/03/2019

Description

Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with elevated privileges on the system via a malicious program.exe executable in the %SYSTEMDRIVE% folder.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nsclient:nsclient\+\+:*:*:*:*:*:*:*:* 0.4.1.73 (excluding)