File Upload Vulnerability in Faronics Insight on Windows
CVE-2023-28353

8.8HIGH

Key Information:

Vendor

Faronics

Status
Vendor
CVE Published:
31 May 2023

What is CVE-2023-28353?

A vulnerability exists in Faronics Insight version 10.0.19045 for Windows, allowing unauthenticated attackers to upload arbitrary files to any location on the Teacher Console's system. This could facilitate various exploitation techniques, including executing malicious code. Additionally, malicious actors can potentially combine this weakness with other vulnerabilities to trigger the immediate execution of a DLL file as NT AUTHORITY/SYSTEM, leading to elevated privileges and further compromise of the affected system.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-28353 : File Upload Vulnerability in Faronics Insight on Windows