logo

Netop Vision Pro – Distance Learning Software is 20/20 in Hindsight

ID: 326642c9-05da-5430-ad0f-85cf4a1703f2

STIX ID: report--326642c9-05da-5430-ad0f-85cf4a1703f2

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2021-03-22

Date Updated: 2026-04-28

Author: Sam Quinn

...
...

McAfee Labs analyzed Netop Vision Pro (used in K-12 environments) and discovered four critical vulnerabilities that enable plaintext leakage of credentials and screenshots, improper authorization and default permissions, and local/remote privilege escalation culminating in unauthenticated remote code execution as SYSTEM within the same local network. The researchers reverse-engineered the proprietary protocol, built PoC tooling to emulate teacher traffic and MChat message flows to overwrite plugins and execute arbitrary binaries, demonstrated the impact and scale (potential wormability across school devices), and coordinated disclosure with Netop, which released mitigations in version 9.7.2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.