NoMachine
cpe:2.3:a:nomachine:nomachine:*:*:*:*:*:*:*
A local privilege escalation vulnerability has been identified in NoMachine Server. This issue arises from the product loading an OpenSSL configuration file from an unsecured location, creating an uncontrolled search path element. Local attackers who can execute low-privileged code on the target system can exploit this vulnerability to escalate privileges and execute arbitrary code within the context of the service account.
Exploitation of this vulnerability allows local attackers to escalate privileges and execute arbitrary code in the context of the service account.
NoMachine has released patches for this vulnerability in versions 8.17.2 and 9.1.24.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.