CVE-2018-6947 – NoMachine < 6.0.80 (x86) - 'nxfuse' Privilege Escalation
https://notcve.org/view.php?id=CVE-2018-6947
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of service for Windows 8 and 10. Una variable de pila no inicializada en el componente nxfuse de la biblioteca Open Source DokanFS incluida en NoMachine, en versiones 6.0.66_2 y anteriores, permite que un usuario local con pocos privilegios eleve sus privilegios en Windows 7 (32 y 64 bits) y que provoque una denegación de servicio (DoS) en Windows 8 y 10. NoMachine versions prior to 6.0.80 (x64) suffer from an nxfuse privilege escalation vulnerability. • https://www.exploit-db.com/exploits/44167 https://www.exploit-db.com/exploits/44168 https://www.fidusinfosec.com/nomachine-road-code-execution-without-fuzzing-cve-2018-6947 https://www.nomachine.com/SU02P00194 https://www.nomachine.com/SU02P00195 https://www.nomachine.com/TR02P08408 • CWE-665: Improper Initialization •
CVE-2017-12763 – NoMachine 5.3.9 - Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2017-12763
An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to local files. Una utilidad del servidor sin especificar en NoMachine en versiones anteriores a la 5.3.10 en Mac OS X y Linux permite que usuarios autenticados obtengan privilegios obteniendo acceso a archivos locales. • https://www.exploit-db.com/exploits/42460 https://www.nomachine.com/SU08O00185 https://www.nomachine.com/forums/topic/security-advisory-nomachine-privileges-escalation-vulnerability • CWE-276: Incorrect Default Permissions •