|
Family: Windows --> Category: infos
DameWare NT Utilities Authentication Credentials Persistence Weakness Vulnerability Scan
Vulnerability Scan Summary Checks for authentication credentials persistence weakness in DameWare NT Utilities
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote Windows host contains an application that is prone to
a privilege escalation issue.
Description :
According to its version number, the copy of DameWare NT Utilities
installed on the remote host allows a local user to recover
authentication credentials because the application stores sensitive
information in memory as plain text: username, password, remote user,
and remote hostname.
See also :
http://www.shellsec.net/leer_advisory.php?id=7
http://archives.neohapsis.com/archives/bugtraq/2005-04/0225.html
http://www.dameware.com/support/security/bulletin.asp?ID=SB5
Solution :
Upgrade to DameWare NT Utilities 3.80 / 4.9 or later.
Threat Level:
Low / CVSS Base Score : 2
(AV:L/AC:H/Au:R/C:P/A:P/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|