Vulnerabilities > CVE-2007-3201 - Unspecified vulnerability in Winpt 1.2.0

047910
CVSS 7.1 - HIGH
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
COMPLETE
Availability impact
NONE
network
winpt
exploit available

Summary

Visual truncation vulnerability in Windows Privacy Tray (WinPT) 1.2.0 allows user-assisted remote attackers to install a key listed under the wrong user ID, and possibly cause the user to encrypt a victim's correspondence with this attacker-supplied key, via a key ID composed of the attacker's user ID, space characters, an invalid WinPT message, additional space characters, and the victim's user ID.

Vulnerable Configurations

Part Description Count
Application
Winpt
1

Exploit-Db

descriptionWindowsPT 1.2 User ID Key Spoofing Vulnerability. CVE-2007-3201. Remote exploit for windows platform
idEDB-ID:30169
last seen2016-02-03
modified2007-06-11
published2007-06-11
reporternnposter
sourcehttps://www.exploit-db.com/download/30169/
titleWindowsPT 1.2 User ID Key Spoofing Vulnerability