Security Flaw in Symantec Ghost 7.0 Exposes User Credentials
CVE-2002-0345

Currently unrated

Key Information:

Vendor

Symantec

Vendor
CVE Published:
25 June 2002

What is CVE-2002-0345?

Symantec Ghost 7.0 has a vulnerability where it stores usernames and passwords in plaintext within the NGServer\params registry key. This insecure storage method can potentially allow unauthorized users to access sensitive information, leading to privilege escalation. Attackers could exploit this flaw to gain high levels of access to system resources, including the ability to manipulate system settings and data.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.