CVE-2023-27470: N-able Take Control

High severity, CVSS 7.0. EPSS: 0.5% chance of exploitation in the next 30 days.

BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.

Affected products

  • N-able Take Control: before 7.0.43 (fixed in 7.0.43)

Published 2023-09-11. Last modified 2026-06-17.