PT-2026-25677 · Truesec · Lapswebui
CVE-2025-15554
·
Publicado
2026-03-16
·
Atualizado
2026-03-16
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Truesec’s LAPSWebUI versions prior to 2.4
Description
The software stores Local Admin Password Solution (LAPS) passwords in the browser cache. An attacker gaining access to a workstation can potentially elevate their privileges by obtaining these disclosed local administrator passwords.
Recommendations
Update Truesec’s LAPSWebUI to version 2.4 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Lapswebui