The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable.
This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.
Metrics
Affected Vendors & Products
References
History
Wed, 21 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Milner
Milner imagedirector Capture |
|
| Vendors & Products |
Milner
Milner imagedirector Capture |
Tue, 20 Jan 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable. This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808. | |
| Title | Hardcoded Encryption Key Enables Database Credential Access in Milner ImageDirector Capture | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: SRA
Published:
Updated: 2026-01-20T21:36:00.681Z
Reserved: 2025-09-04T15:27:48.361Z
Link: CVE-2025-58740
No data.
Status : Received
Published: 2026-01-20T22:15:51.343
Modified: 2026-01-20T22:15:51.343
Link: CVE-2025-58740
No data.