CVE-2018-6384: Nsclient Nsclient++

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with elevated privileges on the system via a malicious program.exe executable in the %SYSTEMDRIVE% folder.

Affected products

  • Nsclient Nsclient++: before 0.4.1.73 (fixed in 0.4.1.73)

Published 2018-01-31. Last modified 2026-06-17.