Vulnerability Description
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can trivially extract these cleartext keystrokes, potentially enabling them to obtain PII and/or to compromise personal accounts owned by the victim.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Faronics | Insight | 10.0.19045 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://research.nccgroup.com/2023/05/30/technical-advisory-multiple-vulnerabiliExploitThird Party Advisory
- https://research.nccgroup.com/?research=Technical%20advisoriesThird Party Advisory
- https://research.nccgroup.com/2023/05/30/technical-advisory-multiple-vulnerabiliExploitThird Party Advisory
- https://research.nccgroup.com/?research=Technical%20advisoriesThird Party Advisory
FAQ
What is CVE-2023-28351?
CVE-2023-28351 is a vulnerability with a CVSS score of 3.3 (LOW). An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A loca...
How severe is CVE-2023-28351?
CVE-2023-28351 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28351?
Check the references section above for vendor advisories and patch information. Affected products include: Faronics Insight, Microsoft Windows.