The Windows Operating System allows for a language bar to be docked in the task bar or floating on the desktop. This configuration provides language bar accessibility in the two AVEVA Access Anywhere browsers.
By manipulating the Windows OS language bar, it is possible to open an Operating System command prompt. Escaping the context of the browser-based application then a user can control the host device in various manners by issuing Operating System commands. The security context of the commands is relative to the escaping user’s security privileges.
Actions and/or Recommendations
About REAL Matters and Mangan Inc.
REAL Matters advisories are published to communicate cybersecurity threats and risks within the Operational Technology (OT) environment and where Critical Infrastructure vulnerabilities are identified. The purpose of this newsletter is to inform, propose suggested approaches to mitigate the risk as well as provide feedback on how Mangan Cybersecurity is approaching the issue(s) addressed.
Mangan Inc. is a nationally-recognized Specialty Engineering, Automation, and Integration company, providing a full-range of services to the Oil & Gas, Refining, Pipeline, Chemicals, and Life Sciences Industries. Established in Long Beach, California in 1990, Mangan’s multiple office locations include sites in California, Georgia, New Hampshire, North Carolina, Texas, and Louisiana. Mangan’s 350+ employee-owners bring expertise, innovation, and safety as their core mission to some of the largest companies in the world.