Windows 版 UpSignOn 7.19.0 之前的版本存在敏感数据泄露漏洞,允许本地攻击者在应用锁定后仍能从进程内存中恢复明文保险库数据。攻击者可利用 PROCESS_VM_READ 权限读取 UpSignOn.exe 的内存空间,并提取敏感字段,包括条目名称、URL、用户名、密码、TOTP 密钥和备注。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Septeo IT Solutions | UpSignOn | < 7.19.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Septeo IT Solutions | UpSignOn | 0 ~ 7.19.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75135 | 6.1 MEDIUM | UpSignOn < 7.19.0 Sensitive Key Retention in Memory |
| CVE-2026-75136 | 6.1 MEDIUM | UpSignOn < 7.19.0 Biometric Key Exposure via Windows PasswordVault |
No comments yet