ClickShare presentation devices riddled with vulnerabilities

By
Follow google news

PowerPwned presentations.

Enterprise staff using the popular Barco ClickShare wireless presentation tools have been warned to update the devices as soon as possible, after security researchers found multiple serious vulnerabilities in them.

ClickShare presentation devices riddled with vulnerabilities
Source: Barco

Security vendor F-Secure says it has discovered twelve separate vulnerabilties in the Clickshare Button range of presentation devices, as well as the base wireless unit and client software from Barco.

Exploiting the vulnerabilties could pose a significant threat allowing attackers to compromise the Button presentation devices, the F-Secure analysis showed.

"Multiple vulnerabilities have been identified that ultimately allow attackers to compromise hardware units and backdoor them, execute arbitrary code on end users' systems, as well as observe and manipulate contents being presented," F-Secure Labs wrote.

Malware can be injected into corporate devices via compromised Button systems, which use system-on-a-chip integrated circuits with known vulnerabilities. 

F-Secure informed Barco of the vulnerabilties in early October this year.

The wireless presentation tool vendor has acknowledged the flaws, and has begun issuing fixes for them this month.

Barco devices are sold in Australia, and the vendor claims it has shipped over a hundred thousand units worldwide.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

Health and Aged Care CISO retires

Health and Aged Care CISO retires

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?