PT-2026-84857 · Upsignon · Upsignon
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
UpSignOn for Windows versions prior to 7.19.0
Description
A sensitive data exposure issue exists where local attackers can recover the master password and decrypt vault contents. This is possible by reading a retained backup key from the process memory of
UpSignOn.exe, which remains accessible even after the vault has been re-locked. Attackers can use this backup key to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt, subsequently using the recovered master password to decrypt the main vault and export all password manager entries in cleartext.Recommendations
Update to version 7.19.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Upsignon