CVE-2007-4415 describes a local privilege escalation vulnerability affecting Cisco VPN Client on Windows versions prior to 5.0.01.0600, including the 5.0.01.0600 InstallShield release. The vulnerability stems from weak permissions on the cvpnd.exe executable, allowing local interactive users to modify it and gain elevated privileges. With a CVSS score of 6.8, this vulnerability has high impact on confidentiality, integrity, and availability, requiring local access and user authentication. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.0.01CPE matchmatch criteria | cpe:2.3:a:cisco:vpn_client:*:*:windows:*:*:*:*:* | ||
5.0.01.0600CPE matchmatch criteria | cpe:2.3:a:cisco:vpn_client:5.0.01.0600:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:S/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.