CVE-2023-28347: Faronics Insight

Critical severity, CVSS 9.6. EPSS: 2.8% chance of exploitation in the next 30 days.

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabilities within the Teacher Console application and achieve remote code execution as NT AUTHORITY/SYSTEM on all connected Student Consoles and the Teacher Console in a Zero Click manner.

Affected products

  • Faronics Insight: version 10.0.19045 only

Published 2023-05-31. Last modified 2026-06-17.