heise online IT news, features and forums at heise online UK
13 February 2008, 10:22

Checkpoint's SecureClient reveals logon information

There is a vulnerability in the "Auto Local Logon" option of Checkpoint's SecureClient, which allows users to obtain the VPN logon information of other system users. The application stores credentials in the registry (HKLM\Software\Checkpoint\SecuRemote), without setting proper access rights. These may therefore be viewed by anyone. Systems affected are VPN-1 SecuRemote/SecureClient NGX R60 and NGAI R56 for Windows. An update fixes the problem.

Advertisement

See also:

(ehe)

  • Bookmark & Share
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit

Topnews