The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file:



C:\ProgramData\WINSelect\WINSelect.wsd

The path for the affected WINSelect Enterprise configuration file is:

C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd
Advisories
Source ID Title
EUVD EUVD EUVD-2024-36124 The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file: C:\ProgramData\WINSelect\WINSelect.wsd The path for the affected WINSelect Enterprise configuration file is: C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd
Fixes

Solution

The vendor provides a patched version 8.30.xx.903 since May 2024 which can be downloaded from the following URL: https://www.faronics.com/document-library/document/download-winselect-standard   The vendor provided the following changelog: https://www.faronics.com/en-uk/document-library/document/winselect-standard-release-notes


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2025-02-13T17:52:54.797Z

Reserved: 2024-05-29T06:48:49.689Z

Link: CVE-2024-36495

cve-icon Vulnrichment

Updated: 2024-08-02T03:37:05.306Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-24T09:15:09.730

Modified: 2024-11-21T09:22:17.123

Link: CVE-2024-36495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.