BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Windows 7/8 admin account installation password stored in the clear in LSA Secrets Jul 12 2013 09:35AM
Marco Ivaldi (raptor mediaservice net)
Hi,

I've often found this behaviour during security assessments for corporate
Clients.

It should indeed be considered a vulnerability, especially in enterprise
scenarios where for instance it can be leveraged by a regular notebook
user to escalate privileges and be able to access all other corp...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus