Back

HIGH

Authorization Bypass Through User-Controlled Key on Single Connect

Published Feb 17, 2023

Description

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16.

Affected products

Remediation

Vendor solution

Apply the patch on  https://filerepo.krontech.com/index.php/s/VQRlYxpzsECp3UU https://filerepo.krontech.com/index.php/s/VQRlYxpzsECp3UU  

(md5sum: 6fea2b58915854b663f43fdf4516522a, instructions on https://docs.krontech.com/singleconnect-2-16/update-patch-rdp-proxy-idor-vulnerability https://docs.krontech.com/singleconnect-2-16/update-patch-rdp-proxy-idor-vulnerability ) https://docs.krontech.com/singleconnect-2-16/update-patch-rdp-proxy-idor-vulnerability

)  and update the Single Connect (PAM) to version 2.16.1.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TR-CERT
Published Feb 17, 2023
Updated Jun 1, 2026
Reserved Feb 17, 2023
CISA Vulnrichment
Updated Mar 12, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner TR-CERT
Published Feb 17, 2023
Updated Jun 1, 2026
Exploited since n/a
EUVD-2023-12871