CVE-2007-1064
Summary
| CVE | CVE-2007-1064 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-02-22 01:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not drop privileges when the help facility in the supplicant GUI is invoked, which allows local users to gain privileges, aka CSCsf14120. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:L/AC:L/Au:S/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Secure Services Client | 4.0 | All | All | All |
| Application | Cisco | Secure Services Client | 4.0.5 | All | All | All |
| Application | Cisco | Secure Services Client | 4.0.51 | All | All | All |
| Application | Cisco | Security Agent | 5.0 | All | All | All |
| Application | Cisco | Security Agent | 5.1 | All | All | All |
| Application | Cisco | Trust Agent | 1.0 | All | All | All |
| Application | Cisco | Trust Agent | 2.0 | All | All | All |
| Application | Cisco | Trust Agent | 2.0.1 | All | All | All |
| Application | Cisco | Trust Agent | 2.1 | All | All | All |
| Application | Meetinghouse | Aegis Secureconnect Client | windows_platform | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker: Cisco Secure Services Client Lets Local Users Gain System Privileges and Also View Passwords | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Cisco Secure Services Client Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco 802.1X Authentication Deployment Products Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker: Cisco Trust Agent Lets Local Users Gain System Privileges and Also View Passwords | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Cisco - Networking, Cloud, and Cybersecurity Solutions | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| osvdb.org/33049 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.