First published: Tue Jun 12 2007(Updated: )
Microsoft Windows Vista uses insecure default permissions for unspecified "local user information data stores" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka "Permissive User Information Store ACLs Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Vista | =gold | |
Microsoft Windows Vista | =gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2229 has a medium severity rating due to its potential for local users to access sensitive information.
To fix CVE-2007-2229, ensure that proper permissions are set on the local user information data stores in the registry and file system.
CVE-2007-2229 affects users of Microsoft Windows Vista Gold editions, both x86 and x64 architectures.
CVE-2007-2229 can allow local users to obtain sensitive information such as administrative passwords.
Yes, Microsoft released patches to address the vulnerabilities associated with CVE-2007-2229.