Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.10553
Category:Windows
Title:SMB Registry : permissions of WinVNC's key
Summary:NOSUMMARY
Description:Description:


The registry key HKLM\Software\ORL\WinVNC3
is writeable and/or readable by users who are not in the admin group.

This key contains the VNC password of this host, as well
as other configuration setup.

As this program allows remote access to this computer with
the privileges of the currently logged on users, you should
fix this problem.


Solution : use regedt32 and set the permissions of this
key to :

- admin group : Full Control
- system : Full Control
- everyone : No access

Risk factor : High

Cross-Ref: BugTraq ID: 1961
Common Vulnerability Exposure (CVE) ID: CVE-2000-1164
http://www.securityfocus.com/bid/1961
Bugtraq: 20001118 WinVNC 3.3.x (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2000-11/0253.html
XForce ISS Database: winvnc-modify-registry(5545)
https://exchange.xforce.ibmcloud.com/vulnerabilities/5545
CopyrightThis script is Copyright (C) 2000 Renaud Deraison

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.