CVE-2018-6947
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/02/2018
Last modified:
03/10/2019
Description
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of service for Windows 8 and 10.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:nomachine:nomachine:*:*:*:*:*:*:*:* | 6.0.66_2 (including) | |
cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_8:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page