CVE-2007-2229: High severity Microsoft Windows Vista vulnerability
Microsoft Windows Vista uses insecure default permissions for unspecified "local user information data stores" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka "Permissive User Information Store ACLs Information Disclosure Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2229?
CVE-2007-2229 has a medium severity rating due to its potential for local users to access sensitive information.
How do I fix CVE-2007-2229?
To fix CVE-2007-2229, ensure that proper permissions are set on the local user information data stores in the registry and file system.
Who is affected by CVE-2007-2229?
CVE-2007-2229 affects users of Microsoft Windows Vista Gold editions, both x86 and x64 architectures.
What types of sensitive information can be accessed through CVE-2007-2229?
CVE-2007-2229 can allow local users to obtain sensitive information such as administrative passwords.
Was CVE-2007-2229 patched by Microsoft?
Yes, Microsoft released patches to address the vulnerabilities associated with CVE-2007-2229.