vendor:
LogMeIn Client
by:
Alexander Korznikov, Viktor Minin, Yakir Wizman
7,5
CVSS
HIGH
Credentials Disclosure
200
CWE
Product Name: LogMeIn Client
Affected Version From: 1.3.2462
Affected Version To: 1.3.2462
Patch Exists: YES
Related CWE: N/A
CPE: a:logmein:logmein_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Windows Server 2012 R2 64bit
2016
LogMeIn Client v1.3.2462 (64bit) Local Credentials Disclosure
LogMeIn Client v1.3.2462 is vulnerable to local credentials disclosure, the supplied username and password are stored in a plaintext format in memory process. A potential attacker could reveal the supplied username and password in order to gain access to account and associated computers.
Mitigation:
Ensure that credentials are not stored in plaintext in memory process.