Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2017-5634

Description

The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended "Please select booking identification" UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print dialog.

POC

Reference

- https://www.youtube.com/watch?v=2j9gP5Qu2WA

- https://www.youtube.com/watch?v=WSQW0ipnXQg

Github

- https://github.com/ARPSyndicate/cvemon