vendor:
Soroush IM Desktop App
by:
VortexNeoX64
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Soroush IM Desktop App
Affected Version From: 0.15 BETA
Affected Version To: 0.15 BETA
Patch Exists: NO
Related CWE: N/A
CPE: a:soroush:soroush_im_desktop_app
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 1803
2018
Soroush IM Desktop app 0.15 – Authentication Bypass
Attackers can unlock the client app installed on Windows OS(others?) without the passcode and access to all the files, chats, images, and etc. the attacker can then send, receive message of any kind on the behalf of the authorized user. PoC (.NET 4.0 Visual Basic) is provided.
Mitigation:
Ensure that authentication mechanisms are designed to prevent bypassing of authentication.