CVE-2021-33436 Information
Jun 07, 2022
cve
Description
NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and ultimately execute code as NT AUTHORITY\SYSTEM.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Reference
https://knowledgebase.nomachine.com/SU05S00223 https://knowledgebase.nomachine.com/SU05S00224 https://github.com/active-labs/Advisories/blob/master/2021/ACTIVE-2021-001.md https://knowledgebase.nomachine.com/TR05S10236
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.3
Share on: