ZeroHour

CVE-2023-47250

PoC ×2
CVSS 3.1
8.8 high
EPSS
1%p71
Published
()
Modified
Description

In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability to inject keystrokes and perform a keylogging attack.

Vendors
m-privacy
Products
mprivacy-tools, rsbac-policy-tgpro, tightgatevnc
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.