First published: Tue Oct 16 2007(Updated: )
Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalog by reading the IVC file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Expression Media |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5470 is considered a high severity vulnerability due to the exposure of sensitive catalog passwords.
To mitigate CVE-2007-5470, ensure that sensitive files are stored securely and consider using encryption for catalog passwords.
CVE-2007-5470 affects users of Microsoft Expression Media who store catalogs with passwords in cleartext.
Yes, CVE-2007-5470 allows local users to gain unauthorized access to sensitive information by reading the IVC file.
The impact of CVE-2007-5470 is that local attackers can easily retrieve passwords and access potentially critical catalog data.