CVE-2022-36220: Critical severity ethz safe exam browser vulnerability
Published Aug 19, 2022
·Updated
Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.
Affected Software
1 affected component
Ethz Safe Exam Browser Windows<3.4.0
Event History
Aug 19, 2022
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36220?
The severity of CVE-2022-36220 is critical.
2
What is CVE-2022-36220?
CVE-2022-36220 is a kiosk breakout vulnerability in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.
3
Which software versions are affected by CVE-2022-36220?
Safe Exam Browser (Windows) versions lower than 3.4.0 are affected by CVE-2022-36220.
4
How can an attacker exploit CVE-2022-36220?
An attacker can exploit CVE-2022-36220 by leveraging the kiosk breakout vulnerability in Safe Exam Browser (Windows) <3.4.0 to achieve code execution through the browser's print dialog.
5
Is there a fix for CVE-2022-36220?
Yes, upgrading to Safe Exam Browser (Windows) version 3.4.0 or higher will fix CVE-2022-36220.