CVE-2024-42012 Details
Description
GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypted cleartext password. An attacker with Windows admin or debugging rights can therefore steal the user's Blocky password and from there impersonate that local user.
A vulnerability exists in GRAU DATA Blocky versions 2.6.x and 2.7.x on Windows, where passwords are stored encrypted instead of hashed. During login, the encrypted password is decrypted and compared to the user's input. This flaw allows an attacker with Windows admin or debugging rights to steal the user's Blocky password and impersonate them locally.
Users are advised to update Blocky to version 3.1. Instructions for updating can be found on the Blocky for Veeam website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 22, 2025CISA-ADP
Assessed Feb 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.blockyforveeam.com/en/security-bulletin-2024-06-25/ | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.graudata.com/en/products/protection-against-ransomware/blocky-for-veeam/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| GRAU DATA Blocky | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 4, 2025 | CVE Modified | CISA-ADP |
| Jan 22, 2025 | New CVE Received | [email protected] |
Volerion