Encrypted database credentials in LaborOfficeFree
Vulnerability Description
Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read and extract the username and password from the database of 'LOF_service.exe' and 'LaborOfficeFree.exe' located in the '%programfiles(x86)%\LaborOfficeFree\' directory. This user can log in remotely and has root-like privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1344
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Pedro Gabaldón Juliá
- Javier Medina Munuera
- Antonio José Gálvez Sánchez
- Alejandro Baño Andrés
References
Affected Vendor
LaborOfficeFree
View all reports →