>> Intel PROset/Wireless Software Insecure Shared Section Information Disclosure
Title : Intel PROset/Wireless Software Insecure Shared Section Information Disclosure VUPEN ID : VUPEN/ADV-2006-1737 CVE ID : CVE-2006-2316
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-05-09
Technical Description
A vulnerability has been identified in Intel PROset/Wireless Software, which could be exploited by malicious users to obtain sensitive information. This flaw is due to insecure permissions being set on the "\BaseNamedObjects\S24EventManagerSharedMemory" shared section, which could be exploited by local attackers to gain knowledge of sensitive wireless configuration information (e.g. WEP keys or passwords).