CVE-2021-42983: Buffer Overflow
NoMachine Enterprise Client is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Client above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the Buffer Overflow vulnerability affecting NoMachine Enterprise Client?
The vulnerability ID is CVE-2021-42983.
What is the severity of CVE-2021-42983?
The severity of CVE-2021-42983 is high with a CVSS score of 8.8.
Which software versions of NoMachine Enterprise Client are affected by CVE-2021-42983?
NoMachine Enterprise Client versions above 4.0.346 and below 7.7.4 are affected by CVE-2021-42983.
What can an attacker do with CVE-2021-42983?
An attacker can execute arbitrary code in kernel mode or cause a denial of service by exploiting CVE-2021-42983.
Is there a fix available for CVE-2021-42983?
It is recommended to update NoMachine Enterprise Client to a version higher than or equal to 7.7.4 to mitigate CVE-2021-42983.