CVE-2007-4414
published 2007-08-18CVE-2007-4414: Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up…
PriorityP418medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.33%
25.3th percentile
Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the dial-up networking dialog box.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | vpn | — | — |
| cisco | vpn_client | <= 4.8.1 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Local Privilege Escalation Vulnerabilities in Cisco VPN Client
vendor_cisco·2007-08-15·CVSS 6.8
CVE-2007-4414 [MEDIUM] CWE-264 Local Privilege Escalation Vulnerabilities in Cisco VPN Client
Local Privilege Escalation Vulnerabilities in Cisco VPN Client
Two vulnerabilities exist in the Cisco VPN Client for Microsoft
Windows that may allow unprivileged users to elevate their privileges to those
of the LocalSystem account.
A workaround exists for one of the two vulnerabilities disclosed in
this advisory.
Cisco has made free software available to address these
vulnerabilities for affected customers.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070815-vpnclient.
Note: Releases 5.0.7.0240 (beta release) and 5.0.7.0290 (official
release) of the 64-bit version of the Cisco VPN Client had a regression in the
fix for the vulnerability "Local Privilege Escalation Through Default cvpnd.exe
File Permissions". Rele
Cisco
Local Privilege Escalation Vulnerabilities in Cisco VPN Client
vendor_cisco
CVE-2007-4414 Local Privilege Escalation Vulnerabilities in Cisco VPN Client
CVE-2007-4414: Local Privilege Escalation Vulnerabilities in Cisco VPN Client
Two vulnerabilities exist in the Cisco VPN Client for Microsoft Windows that may allow unprivileged users to elevate their privileges to those of the LocalSystem account. A workaround exists for one of the two vulnerabilities disclosed in this advisory. Cisco has made free software available to address these vulnerabilities for affected customers. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070815-vpnclient . Note: Releases 5.0.7.0240 (beta release) and 5.0.7.0290 (official release) of the 64-bit version of the Cisco VPN Client had a regression in the fix for the vulnerability "Local Privilege Escalation Through Default cvpnd.exe File Permiss
GHSA
GHSA-gm7r-3hg9-9wc5: Cisco VPN Client on Windows before 4
ghsa_unreviewed·2022-05-01
CVE-2007-4414 [MEDIUM] GHSA-gm7r-3hg9-9wc5: Cisco VPN Client on Windows before 4
Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the dial-up networking dialog box.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/26459http://securitytracker.com/id?1018573http://www.cisco.com/warp/public/707/cisco-sa-20070815-vpnclient.shtmlhttp://www.securityfocus.com/bid/25332http://www.vupen.com/english/advisories/2007/2903https://exchange.xforce.ibmcloud.com/vulnerabilities/36029http://secunia.com/advisories/26459http://securitytracker.com/id?1018573http://www.cisco.com/warp/public/707/cisco-sa-20070815-vpnclient.shtmlhttp://www.securityfocus.com/bid/25332http://www.vupen.com/english/advisories/2007/2903https://exchange.xforce.ibmcloud.com/vulnerabilities/36029
2007-08-18
Published