PT-2007-1593 · Microsoft+2 · Terminal Service+2

Published

2007-01-09

·

Updated

2017-07-29

·

CVE-2007-0108

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Novell Client version 4.91 SP3
Description The issue concerns the nwgina.dll component in Novell Client, which fails to delete user profiles during a Terminal Service or Citrix session. This allows remote authenticated users to invoke alternate user profiles.
Recommendations For Novell Client version 4.91 SP3, consider disabling the nwgina.dll component as a temporary workaround until a patch is available. Restrict access to Terminal Service or Citrix sessions to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0108

Affected Products

Citrix
Novell Client
Terminal Service