Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73wp-hmmc-88j6

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values.

No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values.

EPSS

Процентиль: 16%
0.00053
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 17 лет назад

No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values.

EPSS

Процентиль: 16%
0.00053
Низкий

Дефекты

CWE-200