vendor:
Einstein
by:
Kozan
7.5
CVSS
HIGH
Local Password Disclosure
CWE
Product Name: Einstein
Affected Version From: Einstein v1.01 (and previous versions)
Affected Version To: Einstein v1.01 (and previous versions)
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Unknown
Einstein v1.01 Local Password Disclosure Exploit
This exploit targets Einstein v1.01 (and previous versions) and allows local users to disclose passwords. The exploit uses the RegOpenKeyEx and RegQueryValueEx functions to retrieve the values of the 'username' and 'password' keys in the 'Softwareeinstein' registry key. It then prints the retrieved username and password to the console.
Mitigation:
Apply the latest version of Einstein that addresses this vulnerability. Limit access to the affected system to trusted users only.