Executive brief
QND is a Windows client application used for administrative management. A local attacker with standard user login credentials can extract embedded administrator credentials (ID and password) from the system due to a hard-coded cryptographic key, potentially leading to unauthorized administrative access and control of the affected PC.
Technical details
The vulnerability is a use of hard-coded cryptographic key (CWE-321) in QND's Windows client component. An attacker with local access and standard user privileges can retrieve the hard-coded key and use it to decrypt stored administrator credentials. The attack requires local login to the Windows PC where the QND client is installed and standard user-level access; no special network connectivity or privilege escalation is needed for the credential theft itself. A successful exploit allows the attacker to obtain the administrator ID and password, enabling full administrative control. Patches have been released by QualitySoft Corporation for affected versions.
Affected products
- QualitySoft Corporation QND Premium Ver. 11.1i and earlier
- QualitySoft Corporation QND Standard Ver. 11.1i and earlier
- QualitySoft Corporation QND Advance Ver. 11.0.9i and earlier
Timeline
- 2026-09-16: disclosed