Quantcast
Channel: Files Date: 2012-02-08 to 2012-02-09 ≈ Packet Storm
Viewing all articles
Browse latest Browse all 25

Zero Day Initiative Advisory 12-023

$
0
0
Zero Day Initiative Advisory 12-023 - This vulnerability allows attackers to remotely obtain domain credentials on vulnerable installations of CA Total Defense Suite UNC Management Web Service. Authentication is not required to exploit this vulnerability. The specific flaw exists within the App_Code.dll service listening by default on TCP ports 34444 and 34443 (SSL). The service allows a remote client to request encrypted domain credentials without authentication. The encryption lacks a salt allowing an attacker with a local installation of CA Total Defense Suite UNC Management Web Service to easily decrypt the credentials.

Viewing all articles
Browse latest Browse all 25

Trending Articles