CyberRota Analysis
AI-GeneratedUpSignOn for Windows versions prior to 7.19.0 is vulnerable to sensitive data exposure, allowing local attackers to extract the backup key from the process memory of UpSignOn.exe. This enables them to recover the master password and decrypt vault contents, potentially exposing all stored password manager entries in cleartext. Organizations using affected versions should prioritize this vulnerability to safeguard sensitive information against local threats.
Original NVD Description
UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locked. Attackers can extract the backup key from process memory to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt, then use the recovered master password to decrypt the main vault and export all password manager entries in cleartext.