Vulnerability Description
In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability to inject keystrokes and perform a keylogging attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| M-Privacy | Mprivacy-Tools | < 4.0.406g |
| M-Privacy | Rsbac-Policy-Tgpro | < 2.0.159 |
| M-Privacy | Tightgatevnc | < 4.1.2-1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-ExecutiExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2023/Nov/13ExploitMailing ListThird Party Advisory
- https://sec-consult.com/en/vulnerability-lab/advisories/index.htmlThird Party Advisory
- https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-mThird Party Advisory
- https://www.m-privacy.de/en/tightgate-pro-safe-surfing/Product
- http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-ExecutiExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2023/Nov/13ExploitMailing ListThird Party Advisory
- https://sec-consult.com/en/vulnerability-lab/advisories/index.htmlThird Party Advisory
- https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-mThird Party Advisory
- https://www.m-privacy.de/en/tightgate-pro-safe-surfing/Product
FAQ
What is CVE-2023-47250?
CVE-2023-47250 is a vulnerability with a CVSS score of 8.8 (HIGH). In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktop...
How severe is CVE-2023-47250?
CVE-2023-47250 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-47250?
Check the references section above for vendor advisories and patch information. Affected products include: M-Privacy Mprivacy-Tools, M-Privacy Rsbac-Policy-Tgpro, M-Privacy Tightgatevnc.