CVE-2018-20029

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows a local user to crash the system, leading to a blue screen of death (BSOD), by accessing uninitialized memory in the DokanFS driver. It requires the attacker to have local access to the Windows 10 machine running the affected version of NoMachine.

Technical Description

The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) because uninitialized memory can be read.

CVSS Vector Analysis

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactNone
Integrity ImpactNone
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$759($500-$1K)
Vendor Response
Grade FPatched in 2633 days

Quick Information

Published

Dec 10, 2018

over 7 years ago

Last Modified

Feb 25, 2026

about 1 month ago

Vendor

dokan-dev

Product

dokany