In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.
References
Link | Resource |
---|---|
https://help.scalefusion.com/docs/security-advisory-for-windows-mdm-agent | |
https://medium.com/nestedif/vulnerability-disclosure-browser-mode-kiosk-bypass-scalefusion-832f5a18ebb6 | Exploit Third Party Advisory |
https://medium.com/nestedif/vulnerability-disclosure-kiosk-mode-bypass-scalefusion-4752dfa2dc59 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-01-11 14:15
Updated : 2024-01-18 19:15
NVD link : CVE-2023-50159
Mitre link : CVE-2023-50159
CVE.ORG link : CVE-2023-50159
JSON object : View
Products Affected
scalefusion
- scalefusion
CWE