• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / Keeper vulnerability to Windows password manager

Keeper vulnerability to Windows password manager

18/12/2017 07:46 by giorgos

Keeper password manager: Well-known Google security researcher Tavis Ormandy has discovered a new vulnerability affecting Microsoft Windows users.

This time around, the bug is in the Keeper password manager application that comes preinstalled in some versions of Windows 10. Ormandy states that discovered a similar vulnerability in August of 2016.keeper 1 - Keeper vulnerability in Windows password manager

Although this bug is not a security flaw in Windows or another Microsoft product, it may expose sensitive Windows user details as attackers could steal their passwords stored in the Keeper password manager.

X X X X X X X X X X X X X X X X posted a demo to prove the vulnerability, explaining that it "allows any website to steal any password".

Microsoft, on the other hand, said it knew the issue and said it was preparing to update the application.

"We know the report for this third party application and its developer will release updates to protect our customers," said a company spokesman.

  • Windows: Serious vulnerability to Malware Protection Engine

The Keeper password manager company detected the defect and immediately released an update to the 11.4.4 version. The app extension for Edge, Chrome, and Firefox browsers is automatically updated.

The Keeper developer reports that the flaw can only be exploited if someone can lead the user to a specially designed page that can take advantage of the flaw.

"This potential vulnerability requires a Keeper user to open a malicious website while logged in to the browser extension. It then falsifies the user data using a "clickjacking" technique so that it can run code with user rights in the browser extension.

Although the flaw does not exist in the Windows operating system itself, it once again raises questions about Microsoft's strategy to promote third-party software. It is currently not known which computers the Keeper is preinstalled with and what agreement.

The good thing is that everyone can disable the app.

  • What can a YouTuber idiot make for clicks?
Keeper vulnerability to Windows password manager was last modified: 18 December, 2017, 7: 59 am by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: NewsDay: 2016, browsers, Edge, I'm sure, manager

You May Also Like

Mobile phone emulation in Chrome, Firefox, Edge and Opera
Edge started displaying ads in the settings
Edge Canary Ability to view Office files

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « oTranscribe: Free application for transcripts
Next Post: Ubuntu: Custom installation by mini CD »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.