CVE-2024-36497: Faronics Winselect

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and disable WINSelect entirely.

Affected products

  • Faronics Winselect: before 8.30.xx.903 (fixed in 8.30.xx.903)
  • Faronics Winselect Standard + Enterprise

Published 2024-06-24. Last modified 2026-06-17.