PT-2026-47344 · Git+1 · Openbullet2
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenBullet2 versions prior to 0.3.3
Description
On Windows, the application allows remote attackers to capture the NTLMv2 hash of the process user. This occurs when a job proxy source is configured with a UNC (Universal Naming Convention) path pointing to a server controlled by the attacker. When the job starts, the application attempts to load proxies from this path, triggering an SMB (Server Message Block) authentication attempt that discloses the NTLMv2 hash, which can then be relayed or cracked offline.
Recommendations
Update to a version newer than 0.3.2.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbullet2