|
IM Lock 2006 Insecure Registry Permissions
|
|
Secunia Advisory:
|
SA19140
|
|
|
Release Date:
|
2006-03-07
|
|
Last Update:
|
2006-04-25
|
|
Popularity:
|
5,612 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Exposure of sensitive information
|
|
Where:
|
Local system
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | IM Lock Home 2006 IM Lock Professional 2006
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2006-1198
|
|
Description: fRoGGz has discovered a vulnerability in IM Lock 2006, which can be exploited by malicious, local users to gain knowledge of potentially sensitive information.
The vulnerability is caused due to IM Lock storing its password in the "SOFTWARE\Microsoft\SvcHst\msnvs\prc" registry key under HKEY_LOCAL_MACHINE with insecure permissions. This registry key is readable and can be decoded by non-privileged users on the system.
The vulnerability has been confirmed in IM Lock Professional 2006 version 2.0.0.1 and also reported in the Home edition. Other versions may also be affected.
Solution: Update to the latest version available from the vendor.
IM Lock Home Edition 2006:
http://www.comvigo.com/imlock_home_edition.htm
IM Lock Professional 2006:
http://www.comvigo.com/imlock_professional.htm
Provided and/or discovered by: fRoGGz, SecuBox Labs.
Changelog: 2006-03-16: Added CVE reference.
2006-04-25: Updated "Solution Status" and "Solution" sections.
Original Advisory: http://secubox.shadock.net/IM_Lock_20...egistry_Permission_Vulnerability.html
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|