SB2019090433 - Insecure cryptographic storage in Defender
Published: September 4, 2019
Security Bulletin ID
SB2019090433
Severity
Medium
Patch available
NO
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insecure cryptographic storage (CVE-ID: N/A)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the software stores token seeds, PAP secrets, and user passwords in Active Directory attributes. Defender passwords are hashed using MD5 in conjunction with a static key for obfuscation, which allows a remote authenticated user to read the computed hash from the defender-user TokenData attribute in Active Directory and then use it in an offline brute force attack.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.