The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials.
References
Link | Resource |
---|---|
http://digihax.com/ | Not Applicable |
http://secunia.com/advisories/28820 | Broken Link |
http://securityreason.com/securityalert/3627 | Broken Link |
http://www.securityfocus.com/archive/1/487735/100/0/threaded | Broken Link Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/27675 | Broken Link Third Party Advisory VDB Entry |
http://www.securitytracker.com/id?1019317 | Broken Link Third Party Advisory VDB Entry |
http://www.vupen.com/english/advisories/2008/0475 | Permissions Required |
https://usercenter.checkpoint.com/usercenter/portal/user/anon/page/supportCenter.psml | Not Applicable |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2008-02-08 02:00
Updated : 2024-01-25 21:31
NVD link : CVE-2008-0662
Mitre link : CVE-2008-0662
CVE.ORG link : CVE-2008-0662
JSON object : View
Products Affected
checkpoint
- vpn-1_secureclient
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource