PT-2007-2494 · Cisco+1 · Cisco Security Agent+3

Published

2007-02-22

·

Updated

2017-07-29

·

CVE-2007-1066

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cisco Secure Services Client (CSSC) versions 4.x Cisco Trust Agent versions 1.x through 2.x Cisco Security Agent (CSA) versions 5.0 through 5.1 Meetinghouse AEGIS SecureConnect Client (affected versions not specified)
Description: The issue allows local users to gain privileges by injecting a thread under ConnectionClient.exe due to an insecure default Discretionary Access Control Lists (DACL) for the connection client GUI.
Recommendations: For Cisco Secure Services Client (CSSC) versions 4.x, update the DACL configuration to secure the connection client GUI. For Cisco Trust Agent versions 1.x through 2.x, modify the default DACL settings to restrict unauthorized access. For Cisco Security Agent (CSA) versions 5.0 through 5.1, reconfigure the DACL for the connection client GUI when a vulnerable Trust Agent has been deployed. For Meetinghouse AEGIS SecureConnect Client, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1066

Affected Products

Cisco Secure Services Client
Cisco Security Agent
Cisco Trust Agent
Meetinghouse Aegis Secureconnect Client