PT-2026-84858 · Unknown · Upsignon For Windows
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
UpSignOn for Windows versions prior to 7.19.0
Description
Insecure credential storage allows local attackers to retrieve the biometric unlock key stored in the Windows PasswordVault API without triggering an authentication prompt. A standard local process within the same Windows session can access this biometric key to decrypt protected vault files and export the entire password manager contents in cleartext.
Recommendations
Update UpSignOn for Windows to version 7.19.0 or later.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Upsignon For Windows