SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#821865

CREDANT Mobile Guardian Shield fails to remove credentials from memory

Overview

CREDANT Mobile Guardian Shield fails to properly remove credentials from memory, which may allow an attacker to obtain access to the Windows domain and encrypted drive contents.

I. Description

CREDANT Mobile Guardian (CMG) Shield is a component of Mobile Guardian Enterprise Edition. CMG Shield provides policy-based encryption of specified files. CMG Shield fails to properly clear credentials out of system memory. The default configuration for CMG Shield does not encrypt the Windows pagefile, which means that the credentials may be written to disk. Please see the CREDANT vendor statement below in this vulnerability note for more details.

II. Impact

An attacker with access to the contents of system memory may be able to retrieve the user's credentials, which can allow access to encrypted files.

III. Solution

Apply an update

This issue is addressed in CMG Enterprise Edition 5.2.1 SP1, which was released on May 1, 2007. Please see the CREDANT support site to obtain the update. Details for this vulnerability are available in the support post titled "Vulnerability in Credant Mobile Guardian Shield for Windows."

Systems Affected

VendorStatusDate NotifiedDate Updated
CREDANT Technologies, Inc.Vulnerable1-Jun-2007

References


http://support.credant.com
http://secunia.com/advisories/25410/

Credit

Thanks to Michael Iacovacci for reporting this vulnerability.

This document was written by Will Dormann.

Other Information

Date Public:2007-05-24
Date First Published:2007-06-01
Date Last Updated:2007-06-01
CERT Advisory: 
CVE-ID(s):CVE-2007-2883
NVD-ID(s):CVE-2007-2883
US-CERT Technical Alerts: 
Metric:0.49
Document Revision:4

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader