The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://securityreason.com/securityalert/3627 | third party advisory broken link |
http://www.securityfocus.com/bid/27675 | vdb entry third party advisory broken link |
https://usercenter.checkpoint.com/usercenter/portal/user/anon/page/supportCenter.psml | not applicable |
http://secunia.com/advisories/28820 | third party advisory broken link |
http://www.securityfocus.com/archive/1/487735/100/0/threaded | mailing list vdb entry third party advisory broken link |
http://www.vupen.com/english/advisories/2008/0475 | vdb entry permissions required |
http://www.securitytracker.com/id?1019317 | vdb entry third party advisory broken link |
http://digihax.com/ | not applicable |