CVE-2021-33436

HIGH

NoMachine for Windows <6.15.1,7.5.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and ultimately execute code as NT AUTHORITY\SYSTEM.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_misc
https://knowledgebase.nomachine.com/TR05S10236
Release Notes, Vendor Advisory x_refsource_misc
https://knowledgebase.nomachine.com/SU05S00224
Release Notes, Vendor Advisory x_refsource_misc
https://knowledgebase.nomachine.com/SU05S00223

Scores

CVSS v3 7.3
EPSS 0.0004
EPSS Percentile 12.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
nomachine/nomachine 6.0.0 - 6.15.1
Published Apr 28, 2022
Tracked Since Feb 18, 2026