PT-2023-31890 · Google+2 · Chromium+2
Armin Weihbold
+2
·
Publicado
2023-12-24
·
Atualizado
2024-09-09
·
CVE-2023-51772
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
One Identity Password Manager versions prior to 5.13.1
Description
The issue allows Kiosk Escape, affecting the product's functionality to reset Active Directory passwords on the login screen of a Windows client. It launches a Chromium-based browser in Kiosk mode. The escape sequence involves waiting for a session timeout, clicking on the Help icon, navigating to a website that offers file upload, accessing cmd.exe from the file explorer window, and launching cmd.exe as NT AUTHORITYSYSTEM.
Recommendations
For versions prior to 5.13.1, update to version 5.13.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Help icon and file upload functionality in the Kiosk mode browser to minimize the risk of exploitation.
Correção
Insufficient Session Expiration
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Chromium
One Identity Password Manager
Windows