The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and disable WINSelect entirely.
Solution:
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://r.sec-consult.com/winselect | third party advisory |
https://www.faronics.com/en-uk/document-library/document/winselect-standard-release-notes | release notes |
http://seclists.org/fulldisclosure/2024/Jun/12 |