예티소프트 VestCert 제품 보안 업데이트 권고

2023-12-13 KRCERT Yetisoft VestCert product security update advisory

https://krcert.or.kr/kr/bbs/view.do?searchCnd=1&bbsId=B0000133&searchWrd=&menuNo=205020&pageIndex=42&categoryCode=&nttId=71261

Thumbnail for 예티소프트 VestCert 제품 보안 업데이트 권고

KrCERT reported an information-disclosure vulnerability in Yetisoft VestCert, software used for certificate-based login to enterprise and institutional services. Attackers could exploit the flaw to steal or delete public-certificate data from user PCs, so organizations should remove the affected component with Yetisoft's deletion tool and rely on patched installers distributed after January 2024. The source provides mitigation guidance for a Korean authentication component and does not attribute the issue to DPRK activity.

Related Reports

« Back