First published: Fri Aug 19 2022(Updated: )
Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ethz Safe Exam Browser | <3.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-36220 is critical.
CVE-2022-36220 is a kiosk breakout vulnerability in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.
Safe Exam Browser (Windows) versions lower than 3.4.0 are affected by CVE-2022-36220.
An attacker can exploit CVE-2022-36220 by leveraging the kiosk breakout vulnerability in Safe Exam Browser (Windows) <3.4.0 to achieve code execution through the browser's print dialog.
Yes, upgrading to Safe Exam Browser (Windows) version 3.4.0 or higher will fix CVE-2022-36220.