In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.
References
Configurations
History
21 Nov 2024, 08:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://help.scalefusion.com/docs/security-advisory-for-windows-mdm-agent - | |
References | () https://medium.com/nestedif/vulnerability-disclosure-browser-mode-kiosk-bypass-scalefusion-832f5a18ebb6 - Exploit, Third Party Advisory | |
References | () https://medium.com/nestedif/vulnerability-disclosure-kiosk-mode-bypass-scalefusion-4752dfa2dc59 - Exploit, Third Party Advisory |
18 Jan 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode. |
18 Jan 2024, 17:56
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Scalefusion
Scalefusion scalefusion |
|
References | () https://medium.com/nestedif/vulnerability-disclosure-kiosk-mode-bypass-scalefusion-4752dfa2dc59 - Exploit, Third Party Advisory | |
References | () https://medium.com/nestedif/vulnerability-disclosure-browser-mode-kiosk-bypass-scalefusion-832f5a18ebb6 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:scalefusion:scalefusion:10.5.2:*:*:*:*:windows:*:* |
11 Jan 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-11 14:15
Updated : 2024-11-21 08:36
NVD link : CVE-2023-50159
Mitre link : CVE-2023-50159
CVE.ORG link : CVE-2023-50159
JSON object : View
Products Affected
scalefusion
- scalefusion
CWE