6.8
CVSSv2

CVE-2007-4415

Published: 18/08/2007 Updated: 15/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 10 | Exploitability Score: 3.1
VMScore: 605
Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Cisco VPN Client on Windows prior to 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco vpn client 5.0.01.0600

cisco vpn client