Security & Compliance

DEVO-2023-0021

Summary

Remote Desktop Manager for macOS is affected by a vulnerability.

Affected Products

Remote Desktop Manager for macOS 2023.3.9.3 and earlier

Change Log

2023-12-06 - Initial publication

Severity

Low

Products

Remote Desktop Manager macOS

Fix Version

2023.3.10.2

Code injection via environment variable

Description

Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.

Remediation and Workarounds

Upgrade to Remote Desktop Manager macOS 2023.3.10.2 or higher.

Severity

4.8 Medium CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/U:Green

Affected Products

Remote Desktop Manager macOS 2023.3.9.3 and earlier

CVE(s)

CVE-2023-6288

Credits

YoKo Kho (@yokoacc) and Fahad Alamri (@r3m0t3nu11) from HakTrak Cybersecurity Squad (HakTrak.com)

Helping organizations control the IT chaos by providing highly-secure password, remote connection and privileged access management solutions.

DEVOLUTIONS

Legal & privacy | infos@devolutions.net

All rights reserved © 2025 Devolutions