PT-2012-5721 · Nomachine · No Machine Nx Web Companion
Published
2012-09-19
·
Updated
2017-08-29
·
CVE-2012-5003
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
No Machine NX Web Companion versions 3.x and earlier
Description
The issue arises from the improper verification of update authenticity in nxapplet.jar, allowing user-assisted remote attackers to execute arbitrary code. This can be achieved by crafting specific parameters, such as
SiteUrl or RedirectUrl, to point to a malicious client.zip update file.Recommendations
For No Machine NX Web Companion versions 3.x and earlier, consider restricting access to updates until a proper fix is applied, and avoid using the
SiteUrl and RedirectUrl parameters with untrusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
No Machine Nx Web Companion