CVE-2023-28351: Low severity faronics insight vulnerability
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can trivially extract these cleartext keystrokes, potentially enabling them to obtain PII and/or to compromise personal accounts owned by the victim.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28351?
CVE-2023-28351 is considered a high severity vulnerability due to its potential impact on user privacy.
How do I fix CVE-2023-28351?
To fix CVE-2023-28351, update Faronics Insight to a version that addresses this vulnerability.
What type of data is compromised in CVE-2023-28351?
CVE-2023-28351 compromises cleartext keystrokes, potentially exposing personally identifiable information (PII).
Who is affected by CVE-2023-28351?
Users of Faronics Insight 10.0.19045 on Windows are affected by CVE-2023-28351.
Can a local attacker exploit CVE-2023-28351 easily?
Yes, a local attacker can easily exploit CVE-2023-28351 given the world-readable directory of logged keystrokes.