Impact
QND uses a hard‑coded cryptographic key, providing a way for a local Windows user who has logged into a PC with the client installed to derive administrator credentials such as an ID and password. The weakness is a form of in‑source cryptographic key storage (CWE‑321), which allows the attacker to obtain sensitive information that the client uses for privileged access.
Affected Systems
The vulnerability affects QualitySoft Corporation’s QND Advance, QND Premium, and QND Standard products. No specific versions are listed, so any installed client should be considered at risk.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local on a Windows PC, where the attacker must already be logged in. If successful, the attacker can obtain credentials, potentially compromising the entire system and future privileged operations.
OpenCVE Enrichment