Security & Compliance

DEVO-2023-0021

Summary

Remote Desktop Manager for macOS is affected by a vulnerability.

Affected Products

Remote Desktop Manager for macOS 2023.3.9.3 and earlier

Change Log

2023-12-06 - Initial publication

Severity

Low

Product

Remote Desktop Manager macOS

Fix Version

2023.3.10.2

Code injection via environment variable

Description

Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.

Remediation and Workarounds

Upgrade to Remote Desktop Manager macOS 2023.3.10.2 or higher.

Severity

4.8 Medium CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/U:Green

Affected Products

Remote Desktop Manager macOS 2023.3.9.3 and earlier

CVE(s)

CVE-2023-6288

Credits

YoKo Kho (@yokoacc) and Fahad Alamri (@r3m0t3nu11) from HakTrak Cybersecurity Squad (HakTrak.com)