CVE-2023-47250
In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability to inject keystrokes and perform a keylogging attack.
- Affected products
- Mprivacy-Tools
- M-privacy Mprivacy-tools
- < 4.0.406g
- M-privacy Rsbac-policy-tgpro
- < 2.0.159
- M-privacy Tightgatevnc
- < 4.1.2-1
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.4% (70th percentile)
- Weakness
- CWE-276
- NVD status
- Modified
- Published
- 2023-11-22
CVE-2023-47250 at NVD
1 known exploit for CVE-2023-47250
Proof-of-concept code and exploit modules indexed by Sploitus