7.1
CVSSv2

CVE-2007-3201

Published: 12/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 715
Vector: AV:N/AC:M/Au:N/C:N/I:C/A:N

Vulnerability Summary

Visual truncation vulnerability in Windows Privacy Tray (WinPT) 1.2.0 allows user-assisted remote malicious users to install a key listed under the wrong user ID, and possibly cause the user to encrypt a victim's correspondence with this attacker-supplied key, via a key ID composed of the attacker's user ID, space characters, an invalid WinPT message, additional space characters, and the victim's user ID.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

winpt winpt 1.2.0

Exploits

source: wwwsecurityfocuscom/bid/24412/info WinPT (Windows Privacy Tray) is prone to a key-spoofing vulnerability because it fails to properly display user-supplied key data An attacker can exploit this issue to trick victim users into encrypting potentially sensitive information with a malicious key that appears to be legitimate WinPT ...