CVE-2007-1066

Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client use an insecure default Discretionary Access Control Lists (DACL) for the connection client GUI, which allows local users to gain privileges by injecting "a thread under ConnectionClient.exe," aka CSCsg20558.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:secure_services_client:4.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_services_client:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_services_client:4.0.51:*:*:*:*:*:*:*
cpe:2.3:a:cisco:security_agent:5.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:security_agent:5.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:trust_agent:1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:trust_agent:2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:trust_agent:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:trust_agent:2.1:*:*:*:*:*:*:*
cpe:2.3:a:meetinghouse:aegis_secureconnect_client:windows_platform:*:*:*:*:*:*:*

History

21 Nov 2024, 00:27

Type Values Removed Values Added
References () http://osvdb.org/33047 - () http://osvdb.org/33047 -
References () http://secunia.com/advisories/24258 - () http://secunia.com/advisories/24258 -
References () http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml - Patch, Vendor Advisory () http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/22648 - () http://www.securityfocus.com/bid/22648 -
References () http://www.securitytracker.com/id?1017683 - () http://www.securitytracker.com/id?1017683 -
References () http://www.securitytracker.com/id?1017684 - () http://www.securitytracker.com/id?1017684 -
References () http://www.vupen.com/english/advisories/2007/0690 - () http://www.vupen.com/english/advisories/2007/0690 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/32625 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/32625 -

Information

Published : 2007-02-22 01:28

Updated : 2024-11-21 00:27


NVD link : CVE-2007-1066

Mitre link : CVE-2007-1066

CVE.ORG link : CVE-2007-1066


JSON object : View

Products Affected

meetinghouse

  • aegis_secureconnect_client

cisco

  • security_agent
  • trust_agent
  • secure_services_client