Caution if you are using Last Pass: Tavis Ormandy, one of the most productive members of Google's Project Zero team, revealed a new security issue in LastPass.
Ormandy said that there is an exploit but for now he has not disclosed it. Let us remind that the researchers of Google's Project Zero disclose vulnerabilities first to the directly interested companies that develop the affected products. Companies have 90 days to secure their product, usually by developing a new version, otherwise the researchers disclose the exploit.
The information is very scarce up to this point, as Ormandy provided it via Twitter:
Oops, new bug in Last Pass that affects version 4.1.42 (Chrome&FF). RCE if you use the “Binary Component”, otherwise they can steal passwords. Preparing a full report.
Oops, new LastPass bug that affects 4.1.42 (Chrome&FF). RCE if you use the "Binary Component", otherwise can steal pwds. Full report on the way. pic.twitter.com/y92vm3Ibxd
— Tavis Ormandy (@taviso) March 20, 2017
It reports that the latest version of LastPass for Google Chrome and Firefox (version 4.1.42), and that the exploit can be used for remote code execution or stealing passwords.
Later it revealed that it has a fully functional exploit that does not display messages on Windows, and is only two lines of code. It also noted that the exploit could work on other platforms as well.
Wrote a quick exploit for another LastPass vulnerability. Only affects version on https://t.co/lGcefN9YXM (3.3.2), report on the way. ¯_(ツ)_/¯ pic.twitter.com/AgjASiQMfJ
— Tavis Ormandy (@taviso) March 16, 2017
LastPass also posted a message on Twitter stating that it is aware of the issue, and that it is working to find a solution.
We are aware of the report by @taviso and our team has put a workaround in place while we work on a resolution. Stay tuned for updates.
— LastPass (@LastPass) March 21, 2017
A little later the company posted a second message stating that the issue was resolved.
The issue reported by Tavis Ormandy has been resolved. Additional clarifications will be provided on our blog soon.
According to the tweet, if you are using the Last Pass application, you do not need to do anything beyond waiting for the company's announcement of the fix that addresses the vulnerability.
