Keystroke Logging Vulnerability in Faronics Insight on Windows
CVE-2023-28351

3.3LOW

Key Information:

Vendor

Faronics

Status
Vendor
CVE Published:
31 May 2023

What is CVE-2023-28351?

A vulnerability in Faronics Insight 10.0.19045 on Windows allows unauthorized access to recorded keystrokes from users utilizing the Student application. These keystrokes are stored in a publicly accessible directory, making them easy targets for local attackers. This flaw has significant implications for user privacy, as it can lead to the exposure of sensitive personal information (PII) and potentially facilitate account compromise.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-28351 : Keystroke Logging Vulnerability in Faronics Insight on Windows