CVE-2021-34688: Low severity remotepc vulnerability
iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read an encrypted version of the system's Personal Key in world-readable %PROGRAMDATA% log files. The encryption is done using a hard-coded static key and is therefore reversible by an attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34688?
CVE-2021-34688 is classified as a moderate severity vulnerability due to potential information disclosure.
How do I fix CVE-2021-34688?
To remediate CVE-2021-34688, upgrade iDrive RemotePC to version 7.6.48 or later.
What type of vulnerability is CVE-2021-34688?
CVE-2021-34688 is an information disclosure vulnerability affecting iDrive RemotePC.
Who is affected by CVE-2021-34688?
Users of iDrive RemotePC versions before 7.6.48 on Windows are affected by CVE-2021-34688.
What data can be compromised with CVE-2021-34688?
CVE-2021-34688 allows a locally authenticated attacker to access an encrypted version of the system's Personal Key.