CVE-2012-5003: Medium severity NoMachine Nx Web Companion vulnerability
nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter that points to a Trojan Horse client.zip update file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5003?
CVE-2012-5003 is considered a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2012-5003?
To fix CVE-2012-5003, update No Machine NX Web Companion to the latest version that addresses this vulnerability.
Which versions of No Machine NX Web Companion are affected by CVE-2012-5003?
CVE-2012-5003 affects versions of No Machine NX Web Companion up to and including 3.5.0-2.
What types of attacks can exploit CVE-2012-5003?
CVE-2012-5003 can be exploited through user-assisted attacks that utilize malicious SiteUrl or RedirectUrl parameters.
Is user intervention required to exploit CVE-2012-5003?
Yes, CVE-2012-5003 requires user interaction to execute the attack by accessing a crafted URL.