Microsoft Baseline Security Analyzer Plaintext Result File Vulnerability
BID:4594
Info
Microsoft Baseline Security Analyzer Plaintext Result File Vulnerability
| Bugtraq ID: | 4594 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 25 2002 12:00AM |
| Updated: | Apr 25 2002 12:00AM |
| Credit: | Discovered by Menashe Eliezer <[email protected]>. |
| Vulnerable: |
Microsoft Baseline Security Analyzer 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft Baseline Security Analyzer Plaintext Result File Vulnerability
Microsoft Baseline Security Analyzer (MBSA) is a tool which scans a Microsoft Windows system and creates a security report including a variety of information about the target system.
MBSA stores result information in an XML file placed in a predictable location. An attacker with local access, or the ability to read known local files, may access this file and gain access to sensitive system information.
Microsoft Baseline Security Analyzer (MBSA) is a tool which scans a Microsoft Windows system and creates a security report including a variety of information about the target system.
MBSA stores result information in an XML file placed in a predictable location. An attacker with local access, or the ability to read known local files, may access this file and gain access to sensitive system information.
References
Microsoft Baseline Security Analyzer Plaintext Result File Vulnerability
References:
References:
- Microsoft Baseline Security Analyzer (Microsoft)