CVE-2005-4696: Low severity Microsoft Windows XP vulnerability
The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key in plaintext in memory of the explorer process, which allows attackers with access to process memory to steal the keys and access the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4696?
CVE-2005-4696 is considered a high severity vulnerability due to its potential to expose sensitive network keys.
How do I fix CVE-2005-4696?
To mitigate CVE-2005-4696, users should upgrade their operating system to a version that does not have this vulnerability, as it specifically affects certain versions of Windows XP.
Who is affected by CVE-2005-4696?
CVE-2005-4696 affects users of Microsoft Windows XP, particularly those running gold or Service Pack 2 versions across multiple editions.
What are the potential impacts of CVE-2005-4696?
The potential impact of CVE-2005-4696 includes unauthorized access to the wireless network by attackers who can extract stored keys from memory.
Is there a workaround for CVE-2005-4696?
There are no effective workarounds for CVE-2005-4696 other than applying system updates or moving to a supported operating system.