Vulnerabilities > CVE-2005-4696 - Information Disclosure vulnerability in Microsoft Windows Wireless Zero Configuration Service

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
microsoft
exploit available

Summary

The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key in plaintext in memory of the explorer process, which allows attackers with access to process memory to steal the keys and access the network.

Vulnerable Configurations

Part Description Count
OS
Microsoft
4

Exploit-Db

descriptionMicrosoft Windows XP Wireless Zero Configuration Service Information Disclosure Vulnerability. CVE-2005-4696 . Local exploit for windows platform
fileexploits/windows/local/26323.cpp
idEDB-ID:26323
last seen2016-02-03
modified2005-10-04
platformwindows
port
published2005-10-04
reporterLaszlo Toth
sourcehttps://www.exploit-db.com/download/26323/
titleMicrosoft Windows XP Wireless Zero Configuration Service Information Disclosure Vulnerability
typelocal