PT-2005-5258 · Spb · Spb Kiosk Engine
Published
2005-12-30
·
Updated
2018-10-19
·
CVE-2005-4590
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Spb Kiosk Engine version 1.0.0.1
Description
The issue allows local users to bypass restrictions on allowed applications. This can be achieved through removable media containing a program that will execute due to the autorun setting, or through applications that can invoke other applications. For example, a file: URL specifying a .exe file can be used to execute an application.
Recommendations
For Spb Kiosk Engine version 1.0.0.1, consider disabling the autorun setting for removable media to prevent unauthorized execution of programs. Additionally, restrict the ability of applications to invoke other applications to minimize the risk of bypassing restrictions.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spb Kiosk Engine