|
Microsoft Windows XP Home & Professional contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a local non-privileged user is allowed to retrieve configured wireless profiles using the "WZCQueryInterface()" API via the Wireless Zero Configuration service (wzcsapi.dll), which will disclose configured SSIDs, WEP keys, or the PMK (Pairwise Master Key) that is used for pre-shared key authentication in WPA (Wi-Fi Protected Access), resulting in a loss of confidentiality. Additionally, the explorer process stores the same information in plaintext offering an additional method to gain the information.
|