CVE-2025-58742
Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect client authentication.This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.17%
- CWE
- CWE-522, CWE-923
- Published
- 2026-01-20
- Last modified
- 2026-03-13
Affected products
- Milner ImageDirector Capture
Weakness type
Related vulnerabilities
- CVE-2026-69805 — .NET Elevation of Privilege Vulnerability
- CVE-2026-64918 — Microsoft Office Spoofing Vulnerability
- CVE-2026-81381 — GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
- CVE-2026-77909 — Azure CycleCloud Information Disclosure Vulnerability
- CVE-2026-82070 — Insufficiently Protected Credentials in MongoDB Server Diagnostic Reporting Interface
- CVE-2026-86600 — Workload identity attestation generated before login host validation in Snowflake drivers
- CVE-2026-86726 — AVideo through 29.0 Information Disclosure via restreamsActive.json.php
- CVE-2026-61516 — Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint