Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Windows No-IP动态更新客户端 DUC注册key 本地信泄露漏洞
Vulnerability Description
Windows No-IP动态更新客户端(DUC) 2.2.1版本为HKLM\SOFTWARE\Vitalwerks\DUC注册key使用弱许可,这使得本地用户可以通过读取(1)TrayPassword,(2)用户名,(3)密码,和(4)主机注册值,获得模糊的密码和其他敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A