CVE-2023-47251
In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the VNC service allows authenticated attackers (with access to a VNC session) to automatically transfer malicious PDF documents by moving them into the .spool directory, and then sending a signal to the VNC service, which automatically transfers them to the connected VNC client's filesystem.
- Affected products
- Vnc, Mprivacy-Tools
- M-privacy Mprivacy-tools
- < 2.0.406g
- M-privacy Tightgatevnc
- < 4.1.2-1
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 1.7% (76th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2023-11-22
CVE-2023-47251 at NVD
1 known exploit for CVE-2023-47251
Proof-of-concept code and exploit modules indexed by Sploitus