First published: Sat Dec 31 2005(Updated: )
The Microsoft Wireless Zero Configuration system (WZCS) allows local users to access WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key via certain calls to the WZCQueryInterface API function in wzcsapi.dll.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =gold | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4697 is considered a high-severity vulnerability as it allows local users to access sensitive WEP keys and WPA pre-shared keys.
To mitigate CVE-2005-4697, users should apply the latest security patches provided by Microsoft for Windows XP.
CVE-2005-4697 primarily affects users on Microsoft Windows XP, specifically those using versions such as 'Gold' or 'SP2'.
CVE-2005-4697 is classified as a local privilege escalation vulnerability that compromises wireless security.
A potential workaround for CVE-2005-4697 is to disable the Wireless Zero Configuration service to prevent access to the WEP keys.