FrontRange DSM 7.2.1.2020 / 7.2.2.2331 Insecure Storage

Discussion in 'News Aggregator' started by Packet Storm, 1 May 2015.

  1. Packet Storm

    Packet Storm Guest

    The client management solution FrontRange Desktop and Server Management (DSM) stores and uses sensitive user credentials for required user accounts in an insecure manner which enables an attacker or malware with file system access to a managed client, for example with the privileges of a limited Windows domain user account, to recover the cleartext passwords. The recovered passwords can be used for privilege escalation attacks and for gaining unauthorized access to other client and/or server systems within the corporate network as at least one FrontRange DSM user account needs local administrative privileges on managed systems. Versions 7.2.1.2020 and 7.2.2.2331 are affected.

    Continue reading...
     

Share This Page

Loading...