Microsoft Security Advisory Adv180029 for Sennheiser software
#1
Information 
[Image: sennheiser-windows-advisory.png]
Quote:Microsoft published a security advisory today under ADV180029  -- Inadvertently Disclosed Digital Certificates Could Allow Spoofing -- that warns users and administrators about two Sennheiser software programs that may have introduced vulnerabilities on Windows devices they were installed on.

The two Sennheiser products HeadSetup and HeadSetup Pro installed root certificates on systems they were installed on. Users, who had to run the installer with elevated privileges because of that, were not informed about that.

Older versions of the application placed the private key and the certificate in the installation folder which in itself is not a good practice. Sennheiser used the same private key for all software installations of Sennheiser HeadSetup 7.3 or older.

Anyone, who installed the software on a computer system or got hold of the private key, could potentially abuse it because of that. An attacker could issue certificates on the system the software is installed on.

The certificate is self-signed, marked as a CA certificate and valid until January 13, 2027 when installed. The installer "pushes the certificate into the local machine trusted root certificate store of the Windows system on which it is installed".
Full reading: https://www.ghacks.net/2018/11/28/micros...-software/
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
XYplorer
What's new in Rele...Kool — 08:50
QOwnNotes
26.3.3  Added sma...Kool — 08:47
KeePass 2.61
KeePass 2.61 KeePa...harlan4096 — 16:59
Vivaldi 7.8 Build 3925.76
Vivaldi 7.8 Build ...harlan4096 — 16:57
HWiNFO v8.44
HWiNFO v8.44 Re...harlan4096 — 16:57

[-]
Birthdays
Today's Birthdays
avatar (41)ARYsahulatbazar
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu

[-]
Online Staff
There are no staff members currently online.

>