CVE-2024-23739: Critical severity Discord Discord vulnerability
An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the RunAsNode setting in Discord for macOS to prevent remote attackers from executing arbitrary code (issue affects version 0.0.291 and before).
Discord (macOS) RunAsNode = disabled - Configuration
Disable the enableNodeClilnspectArguments setting in Discord for macOS to prevent remote attackers from executing arbitrary code (issue affects version 0.0.291 and before).
Discord (macOS) enableNodeClilnspectArguments = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23739?
CVE-2024-23739 has been classified as a critical vulnerability due to the risk of remote code execution.
How do I fix CVE-2024-23739?
To fix CVE-2024-23739, update to Discord version 0.0.292 or later.
What versions of Discord are affected by CVE-2024-23739?
Discord versions 0.0.291 and earlier are affected by CVE-2024-23739.
Can CVE-2024-23739 affect my macOS installation?
CVE-2024-23739 specifically affects the Discord application on macOS.
What type of attack is possible with CVE-2024-23739?
CVE-2024-23739 allows remote attackers to execute arbitrary code on the user's system.