PT-2005-5361 · Microsoft · Wireless Zero Configuration

Laszlo Toth

·

Publicado

2005-12-31

·

Atualizado

2017-10-05

·

CVE-2005-4696

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Wireless Zero Configuration system (affected versions not specified)
Description The issue concerns the storage of sensitive network keys in plaintext within the memory of the explorer process. This allows attackers who gain access to the process memory to steal the keys, including WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key, and subsequently access the network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4696

Produtos afetados

Wireless Zero Configuration