Arbitrary Command Execution Vulnerability in NoMachine Software
CVE-2022-48074

5.3MEDIUM

Key Information:

Vendor

Nomachine

Status
Vendor
CVE Published:
3 February 2023

What is CVE-2022-48074?

An issue in NoMachine versions prior to 8.2.3 allows attackers to execute arbitrary commands through a specially crafted .nxs file. This vulnerability can be exploited by attackers to gain unauthorized control and potentially compromise the system’s integrity. Users of NoMachine should ensure they are running the latest version to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.