7.3

CVE-2021-33436

NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and ultimately execute code as NT AUTHORITY\SYSTEM.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NomachineNomachine Version >= 6.0.0 < 6.15.1
   MicrosoftWindows Version-
NomachineNomachine Version >= 7.0 < 7.5.2
   MicrosoftWindows Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.183
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.2 1.9 10
AV:L/AC:H/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/active-labs/Advisories/blob/master/2021/ACTIVE-2021-001.md
Third Party Advisory
https://knowledgebase.nomachine.com/SU05S00223
Vendor Advisory
Release Notes
https://knowledgebase.nomachine.com/SU05S00224
Vendor Advisory
Release Notes
https://knowledgebase.nomachine.com/TR05S10236
Vendor Advisory