Knowledge Base
Searching in : Trouble report
ID:TR09X11975
Added on: 2026-09-11
Last Update: 2026-09-14
Solved in version: 10.1.7; 9.9.6
Platform: All Platforms
Product: NoMachine Server
Severity: Serious
Status: Solved
Print this article

Possible privilege escalation by arbitrary code injection in the 'nxserver --login' process in v10

The handshake protocol of client and nxserver process could be exploited for supplying a crafted command parameter and code execution injection.

SOLVED, Released in version 10.1.7; 9.9.6