Логотип exploitDog
bind:CVE-2020-11005
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-11005

Количество 2

Количество 2

nvd логотип

CVE-2020-11005

почти 6 лет назад

The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a txt file, another executable could be able to decrypt the text using the static method NCryptDecrypt from this same library without the need to use Windows Hello Authentication again. This has been patched in version 1.0.4.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-wvpv-ffcv-r6cw

почти 6 лет назад

Internal NCryptDecrypt method could be used externally from WindowsHello library.

CVSS3: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-11005

The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text and write the output to a txt file, another executable could be able to decrypt the text using the static method NCryptDecrypt from this same library without the need to use Windows Hello Authentication again. This has been patched in version 1.0.4.

CVSS3: 5.1
0%
Низкий
почти 6 лет назад
github логотип
GHSA-wvpv-ffcv-r6cw

Internal NCryptDecrypt method could be used externally from WindowsHello library.

CVSS3: 5.1
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу