Horizon Alert
Summary of the vulnerability and why it matters
An unauthenticated attacker can exploit a flaw in the WorkExaminer Professional console to bypass login and gain administrative control. This vulnerability affects the server used for administrative access, potentially exposing sensitive monitoring data, including user screenshots and keystrokes.
- Attackers bypass console login for admin control.
- Exposes sensitive user monitoring data to unauthorized access.
- Confirm relevance and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can reach the WorkExaminer server on TCP port 12306, bypassing the login prompt by exploiting missing server-side authentication checks. This allows them to gain administrative access, leading to the exposure of sensitive monitoring data, including screenshots and keystrokes.
- Attacker needs network access to the port.
- Bypasses login via missing server checks.
- Gains admin access, exposing sensitive data.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated attacker could gain administrative access to the WorkExaminer server by bypassing login prompts when the server is accessible via TCP port 12306. This could expose sensitive monitoring data, including screenshots and keystrokes of all users.
- Sensitive monitoring data at risk.
- Bypass login via network access.
- Unauthorized access to user data.
Operational Fix
Recommended remediation, mitigation, and detection steps
The WorkExaminer Professional console, used for server administration, is vulnerable due to missing server-side authentication checks. This allows unauthenticated attackers on TCP port 12306 to bypass login, gain administrative access, and access sensitive monitoring data, including screenshots and keystrokes. Infrastructure or platform teams responsible for the WorkExaminer server should prioritize identifying all instances, assessing their network reachability and business criticality, and confirming the accountable owner before planning remediation.
- Infrastructure and platform teams own the issue.
- Verify server reachability and business criticality.
- Plan remediation based on identified risk.