ClickShare presentation devices riddled with vulnerabilities

By
Follow google news

PowerPwned presentations.

Enterprise staff using the popular Barco ClickShare wireless presentation tools have been warned to update the devices as soon as possible, after security researchers found multiple serious vulnerabilities in them.

ClickShare presentation devices riddled with vulnerabilities
Source: Barco

Security vendor F-Secure says it has discovered twelve separate vulnerabilties in the Clickshare Button range of presentation devices, as well as the base wireless unit and client software from Barco.

Exploiting the vulnerabilties could pose a significant threat allowing attackers to compromise the Button presentation devices, the F-Secure analysis showed.

"Multiple vulnerabilities have been identified that ultimately allow attackers to compromise hardware units and backdoor them, execute arbitrary code on end users' systems, as well as observe and manipulate contents being presented," F-Secure Labs wrote.

Malware can be injected into corporate devices via compromised Button systems, which use system-on-a-chip integrated circuits with known vulnerabilities. 

F-Secure informed Barco of the vulnerabilties in early October this year.

The wireless presentation tool vendor has acknowledged the flaws, and has begun issuing fixes for them this month.

Barco devices are sold in Australia, and the vendor claims it has shipped over a hundred thousand units worldwide.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Microsoft releases fix for flawed January security update

Microsoft releases fix for flawed January security update

Starlink faces high-profile security test in Iran crackdown

Starlink faces high-profile security test in Iran crackdown

Single Windows image drove RedVDS disposable cybercrime server business

Single Windows image drove RedVDS disposable cybercrime server business

Microsoft patches single-click Copilot data stealing attack

Microsoft patches single-click Copilot data stealing attack

Log In

  |  Forgot your password?