Remote Code Execution in Ignite Realtime Spark and ROAR Plugin on Windows
CVE-2020-12772
8.8HIGH
What is CVE-2020-12772?
A vulnerability in Ignite Realtime Spark 2.8.3 and its ROAR plugin on Windows allows an attacker to embed an external image in a chat message. When users access this message, the application sends NTLM hashes of their credentials to the attacker's host. This exposure of sensitive user information can lead to credential theft and unauthorized access to user systems. The issue is exacerbated when ROAR is configured for automatic access, increasing the risk of exploitation without user interaction.
