CVE-2024-42012

GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypted cleartext password. An attacker with Windows admin or debugging rights can therefore steal the user's Blocky password and from there impersonate that local user.
Configurations

No configuration.

History

No history.

Information

Published : 2025-01-22 16:15

Updated : 2025-02-04 19:15


NVD link : CVE-2024-42012

Mitre link : CVE-2024-42012

CVE.ORG link : CVE-2024-42012


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials