Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-11005

Опубликовано: 14 апр. 2020
Источник: nvd
CVSS3: 5.1
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a txt file, another executable could be able to decrypt the text using the static method NCryptDecrypt from this same library without the need to use Windows Hello Authentication again. This has been patched in version 1.0.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:windowshello_project:windowshello:*:*:*:*:*:*:*:*
Версия до 1.0.4 (исключая)

EPSS

Процентиль: 4%
0.00019
Низкий

5.1 Medium

CVSS3

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-288
CWE-327

Связанные уязвимости

CVSS3: 5.1
github
почти 6 лет назад

Internal NCryptDecrypt method could be used externally from WindowsHello library.

EPSS

Процентиль: 4%
0.00019
Низкий

5.1 Medium

CVSS3

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-288
CWE-327