PT-2007-2492 · Cisco+1 · Cisco Security Agent+2

Published

2007-02-22

·

Updated

2017-07-29

·

CVE-2007-1064

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cisco Secure Services Client (CSSC) versions 4.x Trust Agent versions 1.x through 2.x Cisco Security Agent (CSA) versions 5.0 through 5.1 Meetinghouse AEGIS SecureConnect Client (affected versions not specified)
Description: The issue allows local users to gain privileges when the help facility in the supplicant GUI is invoked, due to the failure to drop privileges.
Recommendations: For CSSC version 4.x, update to a version that drops privileges when the help facility is invoked. For Trust Agent versions 1.x through 2.x, update to a version that drops privileges when the help facility is invoked. For CSA versions 5.0 through 5.1, update to a version that drops privileges when the help facility is invoked, ensuring the vulnerable Trust Agent is not deployed. For Meetinghouse AEGIS SecureConnect Client, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1064

Affected Products

Cisco Secure Services Client
Cisco Security Agent
Meetinghouse Aegis Secureconnect Client