PT-2024-20047 · Discord · Discord

Giovannipajeu1

·

Published

2024-01-27

·

Updated

2024-02-16

·

CVE-2024-23739

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Discord for macOS version 0.0.291 and before
Description An issue in Discord for macOS allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
Recommendations For Discord for macOS version 0.0.291 and before, update to a version later than 0.0.291 to resolve the issue. As a temporary workaround, consider disabling the RunAsNode and enableNodeClilnspectArguments settings until a patch is available.

Exploit

Fix

Related Identifiers

CVE-2024-23739

Affected Products

Discord