Netop Vision Pro – Distance Learning Software is 20/20 in Hindsight
ID: 326642c9-05da-5430-ad0f-85cf4a1703f2
STIX ID: report--326642c9-05da-5430-ad0f-85cf4a1703f2
Feed Name: McAfee Labs Blog
McAfee Labs analyzed Netop Vision Pro (used in K-12 environments) and discovered four critical vulnerabilities that enable plaintext leakage of credentials and screenshots, improper authorization and default permissions, and local/remote privilege escalation culminating in unauthenticated remote code execution as SYSTEM within the same local network. The researchers reverse-engineered the proprietary protocol, built PoC tooling to emulate teacher traffic and MChat message flows to overwrite plugins and execute arbitrary binaries, demonstrated the impact and scale (potential wormability across school devices), and coordinated disclosure with Netop, which released mitigations in version 9.7.2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
