Product stores RSA private key in a DLL and uses
it to sign a certificate, allowing spoofing of servers and MITM
attacks.
Potential Mitigations
Phase
Description
Sensitive information should not be stored in an executable. Even if
heavy fortifications are in place, sensitive data should be encrypted to
prevent the risk of losing confidentiality.