First published: Fri Feb 23 2007(Updated: )
Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the password field with a hash of a known password, (2) modify timestamps to avoid detection of modifications, (3) remove locks by removing the "is-locked" attribute, and (4) view locked data, which is stored in plaintext.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | ||
Microsoft Windows 2003 Server | =sp2 | |
Microsoft Windows 95 | ||
Microsoft Windows 98 | =gold | |
Microsoft Windows 98SE | ||
Microsoft Windows Me | ||
Microsoft Windows NT | =4.0 | |
Microsoft Windows XP | =gold | |
Mathsoft Mathcad | =12 | |
Mathsoft Mathcad | =13 | |
Mathsoft Mathcad | =13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.