CVE-2018-6384

Description

Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with elevated privileges on the system via a malicious program.exe executable in the %SYSTEMDRIVE% folder.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.06

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-6384 are affected in NSClient++ (x64) 0.3.9Windows
Vulnerabilities CVE-2018-6384 are affected in NSClient++ (x86) 0.3.9Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-347053NSClient++ (x64) (0.8.0)
PATCH-347052NSClient++ (0.8.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234