VYPR
Critical severity9.8NVD Advisory· Published Dec 25, 2023· Updated Jun 17, 2026

CVE-2023-48654

CVE-2023-48654

Description

One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA section, click on the Privacy link, observe that there is a new browser window, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\SYSTEM.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Oneidentity/Password Managerllm-fuzzy2 versions
    <5.13.1+ 1 more
    • (no CPE)range: <5.13.1
    • cpe:2.3:a:oneidentity:password_manager:*:*:*:*:*:*:*:*range: <5.13.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.