CyberRota Analysis
AI-GeneratedA vulnerability in Armoury Crate permits a remote attacker to exploit a permissive cross-domain security policy, potentially allowing them to capture a local user's NTLM hash by tricking the user into visiting a malicious web page. This could lead to unauthorized access to sensitive information and compromise user accounts. Organizations using Armoury Crate should prioritize addressing this issue to mitigate the risk of credential theft.
Original NVD Description
A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application's local service endpoint.Refer to the ' Security Update for Armoury Crate AppĀ ' section on the ASUS Security Advisory for more information.