CVE-2012-5003: Nomachine NX Web Companion

Medium severity, CVSS 6.8. EPSS: 3.2% chance of exploitation in the next 30 days.

nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter that points to a Trojan Horse client.zip update file.

Affected products

  • Nomachine NX Web Companion: up to and including 3.5.0-2; version 1.5.0 only; version 2.0.0-1 only; version 2.1.0-1 only; version 3.0.0-1 only; version 3.0.0-2 only; …

Published 2012-09-19. Last modified 2026-06-16.