Executive brief
NoMachine is a remote desktop and connectivity tool used to access computers over a network. A security flaw in the NoMachine Device Server allows a user who already has limited access to a computer to gain full administrative (SYSTEM) control. This could allow an attacker to bypass security restrictions, access sensitive data, or install malicious software on the affected machine.
Technical details
A local privilege escalation vulnerability exists in the NoMachine Device Server due to an uncontrolled search path element (CWE-427). The application attempts to load a library from an unsecured location, which can be manipulated by a local user. An attacker with low-privileged code execution capabilities on the target system can place a malicious DLL or library in the expected path. When the service loads the library, it executes the attacker's code with SYSTEM-level privileges. This vulnerability is addressed in NoMachine version 9.4.14.
Affected products
- NoMachine NoMachine versions prior to 9.4.14
Timeline
- 2025-12-24: other: Vulnerability reported to vendor
- 2026-03-30: patched: Fixed in NoMachine version 9.4.14
- 2026-03-30: advisory: Coordinated public release by ZDI
- 2026-04-11: disclosed: NVD publication date