This popular presentation tool has some major security flaws

(Image credit: Image Credit: RawPixel / Pexels)

The cybersecurity firm F-Secure has discovered several exploitable vulnerabilities in a popular wireless presentation system the could allow an attacker to manipulate information during presentations, steal passwords and other sensitive information and even install backdoors and other malware.

The firm found the vulnerabilities in Barco's ClickShare wireless presentation system which is a collaboration tool that allows users to present content from a variety of devices.

Senior consultant at F-Secure Consulting, Dmitry Janushkevich explained that the popularity of user-friendly tools makes them the perfect targets for hackers, saying:

“The system is so practical and easy to use, people can’t see any reason to mistrust it. But its deceptive simplicity hides extremely complex inner workings, and this complexity makes security challenging. The everyday objects that people trust without a second thought make the best targets for attackers, and because these systems are so popular with companies, we decided to poke at it and see what we could learn.” 

Barco ClickShare

Janushkevich and his colleagues at F-Secure consulting then began researching the ClickShare system on-an-off for several months after noticing how popular it was during red team assessments. The team discovered multiple exploitable flaws, 10 of which have CVE (Common Vulnerabilities and Exposures) identifiers.

These different issues facilitated a wide variety of attacks including intercepting information shared through the system, using the system to install backdoors or other malware on users' computers and stealing information and passwords. Exploiting some of the vulnerabilities requires physical access but F-Secure consulting also found that others can be executed remotely if the system uses its default settings.

According to Janushkevich, the execution of the exploits in Barco ClickShare can be done quickly by a skilled attacker with physical access (possibly while posing as a cleaner or office worker), allowing them to inconspicuously compromise the device.

F-Secure Consulting shared its research with Barco back in November and the two companies then worked together in a coordinated disclosure effort. Barco has now published a firmware update on their website to mitigate the most critical vulnerabilities though several of the issues involve hardware components that require physical maintenance to address and are unlikely to get fixed.

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
A digital representation of blockchain.
Malicious npm packages use devious backdoors to target users
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
Latest in News
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does
Nintendo Virtual Game Card
Nintendo reveals the new Virtual Game Card feature, an easier way to manage your digital Switch games
Nintendo Switch 2
The Nintendo Switch 2 pre-order date has seemingly been confirmed by Best Buy Canada – here's when you'll be able to order yours
Person printing
Microsoft’s latest Windows 11 update exorcises possessed printers that spewed out pages of random characters
Pro-Ject A1.2 in black, playing a vinyl record in a hi-fi listening room
Pro-Ject's new fully-automatic turntable could be the buy of Record Store Day 2025
Intergalactic: The Heretic Prophet
Intergalactic: The Heretic Prophet reportedly won't release until after 2026, as Neil Druckmann says that staff 'are playing it at the office' right now - but I don't think I can wait that long