vendor:
NoMachine
by:
John Page (aka hyp3rlinx)
7.8
CVSS
HIGH
Trojan File Remote Code Execution
20
CWE
Product Name: NoMachine
Affected Version From: NoMachine <= v5.3.26
Affected Version To: NoMachine <= v5.3.26
Patch Exists: YES
Related CWE: CVE-2018-17980
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
NoMachine Trojan File Remote Code Execution
Possible arbitrary code execution when opening a ".nxs" nomachine file type on client's wintab32.dll preload. This issue regards the client part of all NoMachine installations on Windows (NoMachine free, NoMachine Enterprise Client, NoMachine Enteprise Desktop and NoMachine Cloud Server). 1) create a 32 bit DLL named "wintab32.dll" 2) create an native nomachine ".NXS" file and open it alongside the trojan "wintab32.dll" DLL from Network share or any dir. BOOM!
Mitigation:
Vendor released patch on October 5, 2018