CVE-2023-39107: Critical severity nomachine vulnerability
Published Aug 4, 2023
·Updated
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks.
Affected Software
2 affected components
NoMachine NoMachine<8.8.1
macOS
Event History
Aug 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
06:15 PM
Description
Frequently Asked Questions
1
What is CVE-2023-39107?
CVE-2023-39107 is an arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1.
2
How does CVE-2023-39107 affect NoMachine?
CVE-2023-39107 allows attackers to overwrite root-owned files by using hardlinks in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1.
3
What is the severity of CVE-2023-39107?
The severity of CVE-2023-39107 is critical with a CVSS score of 9.1.
4
How can I fix CVE-2023-39107?
To fix CVE-2023-39107, update NoMachine to version 8.8.1 or later.
5
Is Apple macOS affected by CVE-2023-39107?
No, Apple macOS is not affected by CVE-2023-39107.