CVE-2023-47250
HIGHmprivacy-tools < 2.0.406g - Authenticated X11 Desktop Access Control Bypass via DISPLAY ID
Title source: llmDescription
In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability to inject keystrokes and perform a keylogging attack.
References (5)
Core 5
Core References
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-Execution-Insecure-Permissions.html
Third Party Advisory
https://sec-consult.com/en/vulnerability-lab/advisories/index.html
Third Party Advisory
https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-m-privacy-tightgate-pro/
Exploit, Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2023/Nov/13
Scores
CVSS v3
8.8
EPSS
0.0140
EPSS Percentile
68.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-276
Status
published
Products (3)
m-privacy/mprivacy-tools
< 4.0.406g
m-privacy/rsbac-policy-tgpro
< 2.0.159
m-privacy/tightgatevnc
< 4.1.2-1
Published
Nov 22, 2023
Tracked Since
Feb 18, 2026