Advisory ID: CWERK-2025-1


Title: Exposure of Licensing-Related Sensitive Information in Diagnostic Dumps 
Date: 2024-07-10 
Product Affected: C-Werk 2.0.0 – 2.0.1 
Fixed
: C-Werk 2.0.2

1. Description

Sensitive internal variables, including license validation data, were unintentionally exposed in diagnostic output collected by the built-in troubleshooting tool. Although direct credential leakage was not observed, internal logic values such as timestamps, license state, and registry values were present in plaintext.

2. Solutions and mitigations

The dump collection utility was updated to exclude sensitive registry and memory content. Internal validation logic was refactored to separate sensitive data from support-exported traces.

Customers are advised to upgrade to version 2.0.2 or later. Diagnostic files previously sent to third parties should be reviewed and deleted if necessary.



Back to the list