Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with elevated privileges on the system via a malicious program.exe executable in the %SYSTEMDRIVE% folder.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6384.json"
"2026-04-11T08:05:23Z"
[
{
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/mickem/nscp/commit/29f73db7b1bc770360cbee8837d19e90fa1ac9d4",
"digest": {
"threshold": 0.9,
"line_hashes": [
"260228354333094627802465884612432878615",
"87693210985997050853818432454279036987",
"304047187038373176492570088266603723424",
"162721478261534437172511217501209887244",
"158147576831035243693249491427053018649",
"275943042504529511178364033200420532738",
"258115003050774935591026928821066972859",
"156860257983040846005575981933603884818"
]
},
"id": "CVE-2018-6384-fb6f4c0d",
"deprecated": false,
"target": {
"file": "include/client/command_line_parser.cpp"
}
}
]