VYPR

RunAsSpc

by Robotronic

CVEs (2)

  • CVE-2019-10239HigApr 24, 2019
    risk 0.51cvss 7.8epss 0.00

    Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (under the same user context) to obtain cleartext credentials of the stored account.

  • CVE-2022-26660HigMar 16, 2022
    risk 0.49cvss 7.5epss 0.01

    RunAsSpc 4.0 uses a universal and recoverable encryption key. In possession of a file encrypted by RunAsSpc, an attacker can recover the credentials that were used.