CVE-2023-47250

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/11/2023
Last modified:
30/11/2023

Description

In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability to inject keystrokes and perform a keylogging attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:m-privacy:mprivacy-tools:*:*:*:*:*:*:*:* 4.0.406g (excluding)
cpe:2.3:a:m-privacy:rsbac-policy-tgpro:*:*:*:*:*:*:*:* 2.0.159 (excluding)
cpe:2.3:a:m-privacy:tightgatevnc:*:*:*:*:*:*:*:* 4.1.2-1 (excluding)