cbcvebase.
CVE-2007-4415
published 2007-08-18

CVE-2007-4415: Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to…

PriorityP419medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.32%
23.5th percentile
Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscovpn
ciscovpn_client<= 5.0.01
ciscovpn_client
ciscovpn_client
ciscovpn_client

CVSS provenance

nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.