First published: Tue May 30 2023(Updated: )
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This can compel Student Consoles to connect and put themselves at risk automatically. Connected Student Consoles can be compelled to write arbitrary files to arbitrary locations on disk with NT AUTHORITY/SYSTEM level permissions, enabling remote code execution.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Faronics Insight | =10.0.19045 | |
Microsoft Windows Operating System | ||
Faronics Insight | =10.0.19045 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28349 is considered a significant security vulnerability due to the potential for unauthorized access and control over connected Student Consoles.
To address CVE-2023-28349, update Faronics Insight to version 10.0.19046 or later as soon as it becomes available.
CVE-2023-28349 allows attackers to create malicious programs that imitate the Teacher Console, tricking Student Consoles into establishing a vulnerable connection.
CVE-2023-28349 affects Faronics Insight version 10.0.19045 on Windows.
Yes, CVE-2023-28349 may allow attackers to compromise connected Student Consoles, potentially leading to data exposure and unauthorized access.