Devolutions Remote Desktop Manager 2023.3.9.3 and earlier for macOS: Local Code Injection.
Code Injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.
Vendor / Vendor Homepage:
Devolutions / devolutions[dot]net
Affected Products:
Devolutions Remote Desktop version 2023.3.9.2 and earlier on macOS
Fixed Version:
Devolutions Remote Desktop for macOS version 2023.3.10.2
CVE-ID:
CVE-2023-6288
CVSS Score:
4.8 Medium CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/U:Green
References:
https://devolutions.net/security/advisories/DEVO-2023-0021/
https://www.cve.org/cverecord?id=CVE-2023-6288
YoKo Kho and Fahad Alamri from HakTrak Cybersecurity Squad