Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-4387

Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-312 Almacenamiento de información sensible en texto claro
Fecha de publicación:
29/05/2026
Última modificación:
29/05/2026

Descripción

*** Pendiente de traducción *** StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\\.sdm\state.kv. The file is protected only by default user-level NTFS permissions.<br /> <br /> <br /> <br /> Exploitation requires local read access to the affected user&amp;#39;s profile directory and additional deployment and execution conditions on the target host.<br /> <br /> <br /> <br /> The condition was reported through coordinated disclosure by Hope Walker (SpecterOps).

Referencias a soluciones, herramientas e información