CVE-2007-4415
published 2007-08-18CVE-2007-4415: Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to…
PriorityP419medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.32%
23.5th percentile
Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | vpn | — | — |
| cisco | vpn_client | <= 5.0.01 | — |
| cisco | vpn_client | — | — |
| cisco | vpn_client | — | — |
| cisco | vpn_client | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xw82-gwhg-j9gf: The Cisco VPN Client 5
ghsa_unreviewed·2022-05-14·CVSS 6.8
CVE-2011-2678 [MEDIUM] GHSA-xw82-gwhg-j9gf: The Cisco VPN Client 5
The Cisco VPN Client 5.0.7.0240 and 5.0.7.0290 on 64-bit Windows platforms uses weak permissions (NT AUTHORITY\INTERACTIVE:F) for cvpnd.exe, which allows local users to gain privileges by replacing this executable file with an arbitrary program, aka Bug ID CSCtn50645. NOTE: this vulnerability exists because of a CVE-2007-4415 regression.
GHSA
GHSA-m3q9-2vwv-jcgp: Cisco VPN Client on Windows before 5
ghsa_unreviewed·2022-05-01
CVE-2007-4415 [MEDIUM] GHSA-m3q9-2vwv-jcgp: Cisco VPN Client on Windows before 5
Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe.
Cisco
Local Privilege Escalation Vulnerabilities in Cisco VPN Client
vendor_cisco·2007-08-15·CVSS 6.8
CVE-2007-4414 [MEDIUM] CWE-264 Local Privilege Escalation Vulnerabilities in Cisco VPN Client
Local Privilege Escalation Vulnerabilities in Cisco VPN Client
Two vulnerabilities exist in the Cisco VPN Client for Microsoft
Windows that may allow unprivileged users to elevate their privileges to those
of the LocalSystem account.
A workaround exists for one of the two vulnerabilities disclosed in
this advisory.
Cisco has made free software available to address these
vulnerabilities for affected customers.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070815-vpnclient.
Note: Releases 5.0.7.0240 (beta release) and 5.0.7.0290 (official
release) of the 64-bit version of the Cisco VPN Client had a regression in the
fix for the vulnerability "Local Privilege Escalation Through Default cvpnd.exe
File Permissions". Rele
Cisco
Local Privilege Escalation Vulnerabilities in Cisco VPN Client
vendor_cisco
CVE-2007-4415 Local Privilege Escalation Vulnerabilities in Cisco VPN Client
CVE-2007-4415: Local Privilege Escalation Vulnerabilities in Cisco VPN Client
Two vulnerabilities exist in the Cisco VPN Client for Microsoft Windows that may allow unprivileged users to elevate their privileges to those of the LocalSystem account. A workaround exists for one of the two vulnerabilities disclosed in this advisory. Cisco has made free software available to address these vulnerabilities for affected customers. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070815-vpnclient . Note: Releases 5.0.7.0240 (beta release) and 5.0.7.0290 (official release) of the 64-bit version of the Cisco VPN Client had a regression in the fix for the vulnerability "Local Privilege Escalation Through Default cvpnd.exe File Permiss
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/26459http://securityreason.com/securityalert/3023http://securitytracker.com/id?1018573http://www.cisco.com/warp/public/707/cisco-sa-20070815-vpnclient.shtmlhttp://www.securityfocus.com/archive/1/476812/100/0/threadedhttp://www.securityfocus.com/bid/25332http://www.vupen.com/english/advisories/2007/2903https://exchange.xforce.ibmcloud.com/vulnerabilities/36032http://secunia.com/advisories/26459http://securityreason.com/securityalert/3023http://securitytracker.com/id?1018573http://www.cisco.com/warp/public/707/cisco-sa-20070815-vpnclient.shtmlhttp://www.securityfocus.com/archive/1/476812/100/0/threadedhttp://www.securityfocus.com/bid/25332http://www.vupen.com/english/advisories/2007/2903https://exchange.xforce.ibmcloud.com/vulnerabilities/36032
2007-08-18
Published