CVE-2007-4415: Medium severity Cisco VPN Client vulnerability
Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4415?
CVE-2007-4415 is classified as a high severity vulnerability due to its potential to allow local privilege escalation.
How do I fix CVE-2007-4415?
To fix CVE-2007-4415, users should upgrade to Cisco VPN Client version 5.0.01.0601 or later.
What does CVE-2007-4415 affect?
CVE-2007-4415 affects the Cisco VPN Client on Windows versions before 5.0.01.0600.
What are the consequences of CVE-2007-4415?
The consequences of CVE-2007-4415 include the potential for local users to gain elevated privileges on affected systems.
Who is impacted by CVE-2007-4415?
Users of Cisco VPN Client on Windows who have version 5.0.01 or earlier are impacted by CVE-2007-4415.