Work

CVE-2022-36220

Kiosk escape
Application security

Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.

A bright pink sheet of paper used to wrap flowers curves in front of rich blue background

We cooperated with SafeExamBrowser to research ways to bypass the implemented security safeguards in the SafeExamBrowser Windows application. We ended up finding nothing less than a kiosk escape vulnerability. The vulnerability, being allocated CVE-2022-36220, got rated as a 9.8/10 by NIST with the specific vector being rated as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.