J-Security Center

Title: WhizBang Matrix Screen Saver Password Bypass Vulnerability

Severity: MODERATE

Description:

The Matrix screen saver application (available from a number of sites including www.screentime.com, www.whatisthematrix.warnerbros.com, etc.) may be configured to disallow unauthorized users to access system resources without a password. This is possible using the Password Protected checkbox in the Display Properties of Windows.

A flaw exists in the Matrix screen saver. If the Password Protected checkbox has been enabled, it is possible to bypass it by clicking cancel and pressing numerous arbitrary keys.

It is not confirmed that the Matrix screen saver is using Windows authentication, it is believed that the authentication mechanism being used is the one included with the Matrix screen saver application.

If the screen saver is running under the context of the logged-on system user, the attacker will only have access to resources to which the logged-on system user has access.

Successful exploitation of this vulnerability could lead to the disclosure of sensitive information, possibly assisting in further compromise of the system.

This issue has been confirmed to be vulnerable on Windows 95, 98 and Me.

Affected Products:

  • WhizBang Matrix Screen Saver 0.0.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.