vendor:
IBM i Access Client Solutions
by:
John Page (aka hyp3rlinx)
4.1
CVSS
MEDIUM
Remote Credential Theft
522
CWE
Product Name: IBM i Access Client Solutions
Affected Version From: All
Affected Version To: All
Patch Exists: NO
Related CWE: CVE-2024-22318
CPE: a:ibm:i_access_client_solutions
Platforms Tested: Windows
2024
IBM i Access Client Solutions Remote Credential Theft
IBM i Access Client Solutions (ACS) is vulnerable to remote credential theft when NT LAN Manager (NTLM) is enabled on Windows workstations. By creating UNC paths within ACS configuration files pointing to a malicious server, attackers can capture NTLM hash information and obtain user credentials.
Mitigation:
There is no available fix or patch for this vulnerability at the moment. It is recommended to disable NTLM authentication in IBM i Access Client Solutions to mitigate this issue.