CVE-2024-37742

Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity. By exploiting this flaw, an attacker can bypass exam controls and gain an unfair advantage during exams.
Configurations

No configuration.

History

21 Nov 2024, 09:24

Type Values Removed Values Added
References () https://github.com/Eteblue/CVE-2024-37742 - () https://github.com/Eteblue/CVE-2024-37742 -
References () https://youtu.be/SOm0Hgny_3U - () https://youtu.be/SOm0Hgny_3U -

13 Aug 2024, 01:09

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2

26 Jun 2024, 20:15

Type Values Removed Values Added
Summary
  • (es) Un problema en Safe Exam Browser para Windows anterior a 3.6 permite a un atacante compartir datos del portapapeles entre el modo quiosco SEB y el sistema subyacente, comprometiendo la integridad del examen, lo que puede llevar a la ejecución de código arbitrario y a la obtención de información confidencial a través del componente de administración del portapapeles.
Summary (en) An issue in Safe Exam Browser for Windows before 3.6 allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity which may lead to arbitrary code execution and obtaining sensitive information via the Clipboard Management component. (en) Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity. By exploiting this flaw, an attacker can bypass exam controls and gain an unfair advantage during exams.

25 Jun 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-25 22:15

Updated : 2024-11-21 09:24


NVD link : CVE-2024-37742

Mitre link : CVE-2024-37742

CVE.ORG link : CVE-2024-37742


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control