PT-2024-20047 · Discord · Discord

·

CVE-2024-23739

·

Published

2024-01-27

·

Updated

2024-02-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Discord for macOS version 0.0.291 and before
Description An issue in Discord for macOS allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
Recommendations For Discord for macOS version 0.0.291 and before, update to a version later than 0.0.291 to resolve the issue. As a temporary workaround, consider disabling the RunAsNode and enableNodeClilnspectArguments settings until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-23739

Affected Products

Discord