First published: Thu Jul 15 2021(Updated: )
iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read an encrypted version of the system's Personal Key in world-readable %PROGRAMDATA% log files. The encryption is done using a hard-coded static key and is therefore reversible by an attacker.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iDrive RemotePC | <7.6.48 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.