Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2007-08-18T21:00:00

Updated: 2018-10-15T20:57:01

Reserved: 2007-08-18T00:00:00


Link: CVE-2007-4415

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2007-08-18T21:17:00.000

Modified: 2018-10-15T21:35:14.997


Link: CVE-2007-4415

JSON object: View

cve-icon Redhat Information

No data.