{"api_version":"1","generated_at":"2026-07-23T05:39:24+00:00","cve":"CVE-2007-2229","urls":{"html":"https://cve.report/CVE-2007-2229","api":"https://cve.report/api/cve/CVE-2007-2229.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2229","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2229"},"summary":{"title":"CVE-2007-2229","description":"Microsoft Windows Vista uses insecure default permissions for unspecified \"local user information data stores\" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka \"Permissive User Information Store ACLs Information Disclosure Vulnerability.\"","state":"PUBLISHED","assigner":"microsoft","published_at":"2007-06-12 19:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/2152","name":"http://www.vupen.com/english/advisories/2007/2152","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded","name":"http://www.securityfocus.com/archive/1/471947/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018225","name":"http://www.securitytracker.com/id?1018225","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Windows Vista Discloses Sensitive Information to Local Users","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-032","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-032","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS07-032 - Moderate | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/25623","name":"http://secunia.com/advisories/25623","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Microsoft Windows Vista User Information Disclosure - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/35344","name":"http://osvdb.org/35344","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.us-cert.gov/cas/techalerts/TA07-163A.html","name":"http://www.us-cert.gov/cas/techalerts/TA07-163A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA07-163A -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24411","name":"http://www.securityfocus.com/bid/24411","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Windows Vista Permissive User Information Store ACLs Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1529","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1529","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2229","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2229","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2229","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"*","cpe7":"gold","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2229","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"*","cpe7":"gold","cpe8":"x64","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:33:27.422Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"25623","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25623"},{"name":"MS07-032","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-032"},{"name":"35344","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35344"},{"name":"1018225","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018225"},{"name":"oval:org.mitre.oval:def:1529","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1529"},{"name":"SSRT071438","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"},{"name":"ADV-2007-2152","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2152"},{"name":"TA07-163A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-163A.html"},{"name":"24411","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24411"},{"name":"HPSBST02231","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft Windows Vista uses insecure default permissions for unspecified \"local user information data stores\" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka \"Permissive User Information Store ACLs Information Disclosure Vulnerability.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"25623","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25623"},{"name":"MS07-032","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-032"},{"name":"35344","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35344"},{"name":"1018225","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018225"},{"name":"oval:org.mitre.oval:def:1529","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1529"},{"name":"SSRT071438","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"},{"name":"ADV-2007-2152","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2152"},{"name":"TA07-163A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-163A.html"},{"name":"24411","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24411"},{"name":"HPSBST02231","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2007-2229","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Windows Vista uses insecure default permissions for unspecified \"local user information data stores\" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka \"Permissive User Information Store ACLs Information Disclosure Vulnerability.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"25623","refsource":"SECUNIA","url":"http://secunia.com/advisories/25623"},{"name":"MS07-032","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-032"},{"name":"35344","refsource":"OSVDB","url":"http://osvdb.org/35344"},{"name":"1018225","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018225"},{"name":"oval:org.mitre.oval:def:1529","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1529"},{"name":"SSRT071438","refsource":"HP","url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"},{"name":"ADV-2007-2152","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2152"},{"name":"TA07-163A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA07-163A.html"},{"name":"24411","refsource":"BID","url":"http://www.securityfocus.com/bid/24411"},{"name":"HPSBST02231","refsource":"HP","url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2007-2229","datePublished":"2007-06-12T19:00:00.000Z","dateReserved":"2007-04-24T00:00:00.000Z","dateUpdated":"2024-08-07T13:33:27.422Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-12 19:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_vista:*:gold:*:*:*:*:*:*","matchCriteriaId":"D34A558F-A656-43EB-AC52-C3710F77CDD8"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_vista:*:gold:x64:*:*:*:*:*","matchCriteriaId":"F9DC56EB-EDC4-4DFE-BA9B-B17FF4A91734"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2229","Ordinal":"1","Title":"CVE-2007-2229","CVE":"CVE-2007-2229","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2229","Ordinal":"1","NoteData":"Microsoft Windows Vista uses insecure default permissions for unspecified \"local user information data stores\" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka \"Permissive User Information Store ACLs Information Disclosure Vulnerability.\"","Type":"Description","Title":"CVE-2007-2229"},{"CveYear":"2007","CveId":"2229","Ordinal":"2","NoteData":"2007-06-12","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2229","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}