CVE-2008-2747
Last modified
CVE-2008-2747 is a vulnerability of currently unknown severity. No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| No-Ip | Dynamic Update Client | 2.2.1 |
References
- http://secunia.com/advisories/30714Vendor Advisory
- http://secunia.com/advisories/30714Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2747?
How severe is CVE-2008-2747?
How do I fix CVE-2008-2747?
Are you affected by CVE-2008-2747?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
