PT-2014-6334 · Unity · Unity
Chris Weiss
+8
·
Published
2014-07-31
·
Updated
2017-09-08
·
CVE-2014-5195
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Unity versions prior to 7.2.3
Unity versions 7.3.x prior to 7.3.1
Description
The issue allows physically proximate attackers to bypass the lock screen by leveraging a machine that had text selected when locking or resuming from a suspension, due to Unity not properly taking focus of the keyboard when switching to the lock screen.
Recommendations
For Unity versions prior to 7.2.3, update to version 7.2.3 or later.
For Unity versions 7.3.x prior to 7.3.1, update to version 7.3.1 or later.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unity