McAfee security researchers have discovered several critical vulnerabilities in remote monitoring software used in schools. These vulnerabilities threaten the security and privacy of students, exposing their PCs to cyberattacks.
Specifically, McAfee has uncovered multiple security vulnerabilities in Netop Vision Pro, a popular monitoring software used in schools to help teachers monitor remote teaching sessions. Features of this software include viewing student screens and sharing teachers' screens, applying web filters, forwarding URLs, chat features, and freezing student screens.
Read also: Approximately 80,000 Exchange servers contain exploitable vulnerabilities!
According to McAfee's Advanced Threat Research (ATR) team, Netop Vision Pro contained vulnerabilities that hackers could exploit to gain complete control of students' PCs.

After creating a virtual “classroom” consisting of four devices on a local network, the researchers realized that all network traffic was not encrypted and that there was no option to enable encryption during configuration. In addition, students who started connecting to the class unknowingly began sending screenshots to their teacher. This is due to the fact that there was no encryption. In addition, as McAfee reported, those on the local network could see the content of the students’ screens remotely.
When the teacher starts a session, he sends a network packet asking students to participate. Malicious actors could modify this data as well as perform local privilege escalation (LPE) attacks and eventually gain system privileges.
See also: Top encrypted messaging apps: Everything you need to know!
The chat feature in the software stored files sent by the teacher in a “working” directory, allowing malicious actors to overwrite existing files and send malicious content to students, such as malware that would “infect” their computers. In addition, Netop Vision Pro student profiles broadcast their presence to the network every few seconds, allowing an attacker to scale their attacks across an entire school system.

In total, four critical vulnerabilities were identified in the software, which are tracked as CVE-2021-27192, CVE-2021-27193, CVE-2021-27194, and CVE-2021-27195. The security flaws allowed privilege escalation and remote code execution (RCE) attacks within the compromised network. If a hacker were able to gain complete control of all target systems using the vulnerable software, they could also bridge the gap from a virtual attack to the physical environment. In addition, the hacker could activate cameras and microphones on the target system, which would allow them to monitor a student and their surroundings.

Netop was notified of the security flaws found in its software on December 11, 2020. The latest version of the software, 9.7.2, addressed some of the issues, such as LPE errors and credential encryption. Mitigations have also been added to chat-based read/write issues. Netop plans to develop network encryption in the near future.
Proposal: Record breaches and hacks in American schools in 2020
Last week, the FBI warned of increasing attacks on schools and universities in the US and UK. Law enforcement agencies have also seen a sharp increase in attack attempts using the PYSA ransomware, which aims to steal data before encrypting it in order to blackmail the victim into paying the required ransom.
Source: zdnet.com
