Vulnerabilities (CVE)

Filtered by vendor Mremoteng
Filtered by product Mremoteng
Angry Yack Logo
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-30367 1 Mremoteng 1 Mremoteng 2024-11-21 N/A 7.5 HIGH
Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG version <= v1.76.20 and <= 1.77.3-dev loads configuration files in plain text into memory (after decrypting them if necessary) at application start-up, even if no connection has been established yet. This allows attackers to a ...

Show More

CVE-2020-24307 1 Mremoteng 1 Mremoteng 2024-11-21 N/A 7.8 HIGH
An issue in mRemoteNG v1.76.20 allows attackers to escalate privileges via a crafted executable file. NOTE: third parties were unable to reproduce any scenario in which the claimed access of BUILTIN\Users:(M) is present.