CVE-2023-28351

LOW

Faronics Insight - Log Information Exposure

Title source: rule
STIX 2.1

Description

An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can trivially extract these cleartext keystrokes, potentially enabling them to obtain PII and/or to compromise personal accounts owned by the victim.

Scores

CVSS v3 3.3
EPSS 0.0003
EPSS Percentile 10.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (1)
faronics/insight 10.0.19045
Published May 31, 2023
Tracked Since Feb 18, 2026