CVE-2018-6947 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 3.1% (pctl 87)
Patch early
A public exploit exists.
Description
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of service for Windows 8 and 10.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.09% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-665 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-02-28 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| microsoft | windows 10 |
| microsoft | windows 7 |
| microsoft | windows 8 |
| nomachine | nomachine |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | NoMachine < 6.0.80 (x86) - 'nxfuse' Privilege Escalation | 2018-02-22 |
| exploit-db | NoMachine < 6.0.80 (x64) - 'nxfuse' Privilege Escalation | 2018-02-22 |
References
- https://www.exploit-db.com/exploits/44167/
- https://www.exploit-db.com/exploits/44168/
- https://www.fidusinfosec.com/nomachine-road-code-execution-without-fuzzing-cve-2018-6947/
- https://www.nomachine.com/SU02P00194
- https://www.nomachine.com/SU02P00195
- https://www.nomachine.com/TR02P08408
- https://www.exploit-db.com/exploits/44167/
- https://www.exploit-db.com/exploits/44168/
- https://www.fidusinfosec.com/nomachine-road-code-execution-without-fuzzing-cve-2018-6947/
- https://www.nomachine.com/SU02P00194
- https://www.nomachine.com/SU02P00195
- https://www.nomachine.com/TR02P08408
→ the Explorer · watch your stack · NVD