PT-2005-5361 · Microsoft · Wireless Zero Configuration

Laszlo Toth

·

Published

2005-12-31

·

Updated

2017-10-05

·

CVE-2005-4696

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Wireless Zero Configuration system (affected versions not specified)
Description The issue concerns the storage of sensitive network keys in plaintext within the memory of the explorer process. This allows attackers who gain access to the process memory to steal the keys, including WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key, and subsequently access the network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4696

Affected Products

Wireless Zero Configuration