New Vulnerabilities Found and Patched in LastPass


An article review.


Attackers could have used the exploits to compromise users’ password vaults and execute code on affected machines


ServIcons_ITAudit_01Last week security researchers independently reported two major flaws in LastPass, a popular password management application with users numbering in the millions. While one exploit had been patched for over a year before being disclosed, it could have allowed for remote code execution on victims’ machines. The other exploit involved a malicious site that could remotely perform actions on a LastPass user’s vault, including deleting items.

While it is believed that both exploits were addressed before users were impacted it draws attention to the risks presented by the use of password management applications, which are relied upon by many to help keep track of login credentials and present a centralized point of failure for attackers.

The experts in the article did not go so far as suggesting people stop using managers such as LastPass, but did suggest they not use the auto-fill feature used to automatically enter website credentials as that was the vector for one of the exploits discovered by researchers.

 

 


Original article by Bradley Barth of SC Magazine.


same_strip_012513


 

Related Posts

The Magnificent Seven 2023

Seven Trends . . . …that small bank Information Security Officers face in 2023 Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Welcom...

“Phone Phishing” – Awareness Poster (Re-release)

Another awareness poster for YOUR customers (and users). Now that we have our own employees aware, maybe it’s time to start posting content for our customers!Check out posters.infotex.com for...

“Strong Password Tips” – Awareness Poster

Another awareness poster for YOUR customers (and users). Now that we have our own employees aware, maybe it’s time to start posting content for our customers!Check out posters.infotex.com for...