Lucene search

K
nvd[email protected]NVD:CVE-2023-50159
HistoryJan 11, 2024 - 2:15 p.m.

CVE-2023-50159

2024-01-1114:15:44
web.nvd.nist.gov
3
scalefusion
agent
bypassed
kiosk mode
restrictions
file explorer
fixed
cve-2023-50159

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0

Percentile

5.1%

In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.

Affected configurations

Nvd
Node
scalefusionscalefusionMatch10.5.2windows
VendorProductVersionCPE
scalefusionscalefusion10.5.2cpe:2.3:a:scalefusion:scalefusion:10.5.2:*:*:*:*:windows:*:*

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2023-50159