CVE-2023-28349: High severity faronics insight vulnerability
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This can compel Student Consoles to connect and put themselves at risk automatically. Connected Student Consoles can be compelled to write arbitrary files to arbitrary locations on disk with NT AUTHORITY/SYSTEM level permissions, enabling remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28349?
CVE-2023-28349 is considered a significant security vulnerability due to the potential for unauthorized access and control over connected Student Consoles.
How do I fix CVE-2023-28349?
To address CVE-2023-28349, update Faronics Insight to version 10.0.19046 or later as soon as it becomes available.
What type of attack is associated with CVE-2023-28349?
CVE-2023-28349 allows attackers to create malicious programs that imitate the Teacher Console, tricking Student Consoles into establishing a vulnerable connection.
Which software is affected by CVE-2023-28349?
CVE-2023-28349 affects Faronics Insight version 10.0.19045 on Windows.
Can CVE-2023-28349 lead to data exposure?
Yes, CVE-2023-28349 may allow attackers to compromise connected Student Consoles, potentially leading to data exposure and unauthorized access.