Advisories for Nuget/DSInternals.Common package

2022

DSInternals Credential Roaming Elevation of Privilege Vulnerability

A vulnerability exists in the DSInternals.Common.Data.RoamedCredential.Save() method, which incorrectly parses the msPKIAccountCredentials LDAP attribute values. As a consequence, malicious actor would be able to modify the file system of the computer where an application using this function is executed with administrative privileges. A similar security issue used to be present in the Windows operating system, as DSInternals re-implements the Credential Roaming feature of Windows.