CVE-2013-3496

Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:infotecs:vipnet_client:*:*:*:*:*:*:*:*
cpe:2.3:a:infotecs:vipnet_coordinator:*:*:*:*:*:*:*:*
cpe:2.3:a:infotecs:vipnet_personal_firewall:*:*:*:*:*:*:*:*
cpe:2.3:a:infotecs:vipnet_safedisk:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:53

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2013-05/0072.html - () http://archives.neohapsis.com/archives/bugtraq/2013-05/0072.html -

Information

Published : 2013-05-22 13:29

Updated : 2024-11-21 01:53


NVD link : CVE-2013-3496

Mitre link : CVE-2013-3496

CVE.ORG link : CVE-2013-3496


JSON object : View

Products Affected

infotecs

  • vipnet_safedisk
  • vipnet_personal_firewall
  • vipnet_client
  • vipnet_coordinator
CWE
CWE-264

Permissions, Privileges, and Access Controls