Faronics Insight Multiple Vulnerabilities
ID: ad2dc9a1-41d2-51da-bcb0-a3912fd61561
STIX ID: report--ad2dc9a1-41d2-51da-bcb0-a3912fd61561
Feed Name: NCC Research
This technical advisory from NCC Group documents 11 vulnerabilities in Faronics Insight (teacher and student consoles) that enable high-impact attacks — including unauthenticated remote code execution as SYSTEM via file upload and DLL hijacking, zero-click XSS exploitation from artificial consoles, plaintext HTTP/WebSocket communications enabling MITM, world-readable plaintext keystroke logs, and insufficient access controls. The report includes detailed technical analysis, proof-of-concept exploit chains, CVE identifiers, and remediation recommendations; fixes were released in Insight v11.23.x.289.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
