CVE-2023-48654 Details
Description
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA section, click on the Privacy link, observe that there is a new browser window, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\SYSTEM.
A privilege escalation vulnerability has been identified in the One Identity Password Manager Secure Password Extension, affecting versions prior to 5.13.1. This vulnerability allows a local, pre-authenticated attacker to escape from Kiosk mode and execute commands with SYSTEM privileges on the login screen of a Windows client. The issue arises because the Password Manager Extension, which facilitates Active Directory password resets, launches a Chromium-based browser in Kiosk mode. Exploitation involves navigating through Google ReCAPTCHA links to access external websites, ultimately leading to the execution of command-line applications with elevated permissions.
Users are advised to update to One Identity Password Manager version 5.13.1, which addresses this vulnerability. The update can be downloaded from the One Identity Support Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| oneidentity password manager | < 5.13.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 4, 2025 | CVE Modified | CVE |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 3, 2024 | Initial Analysis | [email protected] |
| Dec 25, 2023 | New CVE Received | [email protected] |