Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with elevated privileges on the system via a malicious program.exe executable in the %SYSTEMDRIVE% folder.
{
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:nsclient:nsclient\\+\\+:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.4.1.73"
}
]
}
"2026-07-08T19:50:50Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6384.json"
[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"260228354333094627802465884612432878615",
"87693210985997050853818432454279036987",
"304047187038373176492570088266603723424",
"162721478261534437172511217501209887244",
"158147576831035243693249491427053018649",
"275943042504529511178364033200420532738",
"258115003050774935591026928821066972859",
"156860257983040846005575981933603884818"
]
},
"deprecated": false,
"source": "https://github.com/mickem/nscp/commit/29f73db7b1bc770360cbee8837d19e90fa1ac9d4",
"target": {
"file": "include/client/command_line_parser.cpp"
},
"id": "CVE-2018-6384-fb6f4c0d",
"signature_version": "v1"
}
]