PT-2019-9594 · Microsoft+1 · Windows+1
Michael Lucas
·
Published
2019-03-18
·
Updated
2025-05-30
·
CVE-2018-18466
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SecurEnvoy SecurAccess version 9.3.502
Description
An issue was discovered in SecurEnvoy SecurAccess. When put in Debug mode and used for RDP connections, the application stores emergency credentials in cleartext in the logs, which can be accessed by anyone. The vendor disputes this as a vulnerability, stating that disclosure of a local account password is only achievable when a custom registry key is added to the Windows registry, requiring administrator access.
Recommendations
For SecurEnvoy SecurAccess version 9.3.502, consider disabling the Debug mode when not necessary, especially for RDP connections, to minimize the risk of exposing emergency credentials. Restrict access to the DEBUG folder to prevent unauthorized access to the logs. As a temporary workaround, avoid using the custom registry key provided by support staff for troubleshooting, unless absolutely necessary, and ensure that administrator access is strictly controlled. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Securenvoy Securaccess
Windows