CVE-2024-7253: NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within nxnode.exe. The process loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
. Was ZDI-CAN-24039.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7253?
CVE-2024-7253 is a high-severity vulnerability that allows local privilege escalation in NoMachine installations.
How do I fix CVE-2024-7253?
To fix CVE-2024-7253, update your NoMachine software to versions 7.15.6 or higher, or 8.12.3 or higher.
What are the affected versions for CVE-2024-7253?
CVE-2024-7253 affects NoMachine versions between 7.0 and 7.15.6, and between 8.0 and 8.12.3.
Who is affected by CVE-2024-7253?
Local attackers who have low-privileged access to a system running vulnerable versions of NoMachine are affected by CVE-2024-7253.
What type of vulnerability is CVE-2024-7253?
CVE-2024-7253 is classified as an uncontrolled search path element local privilege escalation vulnerability.