First published: Tue May 30 2023(Updated: )
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can trivially extract these cleartext keystrokes, potentially enabling them to obtain PII and/or to compromise personal accounts owned by the victim.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Faronics Insight | =10.0.19045 | |
Microsoft Windows Operating System | ||
Faronics Insight | =10.0.19045 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28351 is considered a high severity vulnerability due to its potential impact on user privacy.
To fix CVE-2023-28351, update Faronics Insight to a version that addresses this vulnerability.
CVE-2023-28351 compromises cleartext keystrokes, potentially exposing personally identifiable information (PII).
Users of Faronics Insight 10.0.19045 on Windows are affected by CVE-2023-28351.
Yes, a local attacker can easily exploit CVE-2023-28351 given the world-readable directory of logged keystrokes.