nCipher MSCAPI CSP Install Wizard Incorrect Key Generation Vulnerability

BID:4729

Info

nCipher MSCAPI CSP Install Wizard Incorrect Key Generation Vulnerability

Bugtraq ID: 4729
Class: Configuration Error
CVE: CVE-2002-0939
CVE-2002-0940
Remote: No
Local: Yes
Published: May 13 2002 12:00AM
Updated: Jul 11 2009 12:46PM
Credit: Published in nCipher Security Advisory #3: MSCAPI CSP Install Wizard.
Vulnerable: nCipher MSCAPI CSP 5.54
nCipher MSCAPI CSP 5.50
Not Vulnerable:

Discussion

nCipher MSCAPI CSP Install Wizard Incorrect Key Generation Vulnerability

nCipher produces a range of hardware and software security products. An issue has been reported in version 5.50 of the install wizard for the MSCAPI CSP key generator under Windows 2000.

Under some circumstances, a key generated that should be protected by an Operator card will in fact be generated as only module protected. This may result in weaker security than anticipated, and under some deployments reduce or break the security model.

** It has been reported that a similar issue exists in the command line utility 'domesticinstall.exe' included with versions 5.50 and 5.54.

Exploit / POC

nCipher MSCAPI CSP Install Wizard Incorrect Key Generation Vulnerability

No exploit is required.

Solution / Fix

nCipher MSCAPI CSP Install Wizard Incorrect Key Generation Vulnerability

Solution:
The following fix information has been provided by nCipher:

1. Users who have NOT already created a key with the wrong protection
---------------------------------------------------------------------

In order to force MSCAPI applications to generate cardset protected keys
a file `wizardfix.reg' should be created containing the following text:

------------ CUT HERE --------------
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\nCipher\Cryptography]
"UseModuleKeys"=dword:0000000
------------ CUT HERE --------------

This file can then be run by the user to change the appropriate registry
entry that determines the behavior of key generation using the nCipher
CSP.

Alternatively, the user can edit the registry value specified above
directly using `regedit'.

The registry setting must be reset using either of the above methods
after each invocation of the affected nCipher CSP Install Wizard.

2. Users who have already created a key which is erroneously module
protected
-------------------------------------------------------------------

Users who have already generated keys which were intended to be cardset
protected, but due to this error are not, are advised to apply the above
registry fix and generate new keys. nCipher recommends against
converting existing module-protected keys to cardset-protected status,
since it is extremely difficult to do this in a way that increases
security.

nCipher customers are advised to contact nCipher at [email protected] for information on receiving patches and updates which address this issue.

References

nCipher MSCAPI CSP Install Wizard Incorrect Key Generation Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report