CVE Vulnerabilities

CVE-2021-33436

Published: Apr 28, 2022 | Modified: May 07, 2022
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and ultimately execute code as NT AUTHORITYSYSTEM.

Affected Software

Name Vendor Start Version End Version
Nomachine Nomachine 6.0.0 (including) 6.15.1 (excluding)
Nomachine Nomachine 7.0 (including) 7.5.2 (excluding)

References