Buffer Overflow Vulnerability in NoMachine Cloud Server
CVE-2021-42980

8.8HIGH

Key Information:

Vendor

Nomachine

Vendor
CVE Published:
7 December 2021

What is CVE-2021-42980?

The NoMachine Cloud Server is impacted by a buffer overflow vulnerability within the IOCTL handler 0x22001B. This flaw exists in versions above 4.0.346 and below 7.7.4, allowing local attackers to execute arbitrary code in kernel mode or to cause denial of service, potentially leading to memory corruption and system crashes. Proper mitigation is essential to safeguard against unauthorized access and ensure system integrity.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.