Secunia Security Advisory - A security issue has been reported in IBM Lotus Notes, which can be exploited by malicious, local users to gain escalated privileges.
1cb6bf6b831aa040f4a4f30dbab0aa9fd39cbb08bad73098fb7bfa86b020bf04
----------------------------------------------------------------------
Secunia CSI
+ Microsoft SCCM
-----------------------
= Extensive Patch Management
http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/
----------------------------------------------------------------------
TITLE:
IBM Lotus Notes SURunAs.exe Password Disclosure Security Issue
SECUNIA ADVISORY ID:
SA39507
VERIFY ADVISORY:
http://secunia.com/advisories/39507/
DESCRIPTION:
A security issue has been reported in IBM Lotus Notes, which can be
exploited by malicious, local users to gain escalated privileges.
The security issue is caused due to the SURunAs.exe executable
storing the username and password of a local administrative account
in clear text. This can be exploited to gain administrative
privileges by reading the stored credentials.
The security issue is reported in versions 7.0, 8.0, and 8.5. Other
versions may also be affected.
SOLUTION:
Do not distribute the SURunAs.exe executable to untrusted users.
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.
ORIGINAL ADVISORY:
http://www-01.ibm.com/support/docview.wss?uid=swg21427073
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------