CVE-2007-0436

Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:barron_mccann:install:bms1472:*:*:*:*:*:*:*
cpe:2.3:a:barron_mccann:x-kryptor_driver:bms1446hrr:*:*:*:*:*:*:*
cpe:2.3:a:barron_mccann:x-kryptor_secure_client:*:*:*:*:*:*:*:*
cpe:2.3:a:barron_mccann:xgntr:bms1351:*:*:*:*:*:*:*

History

21 Nov 2024, 00:25

Type Values Removed Values Added
References () http://jvn.jp/niscc/NISCC-462660/index.html - () http://jvn.jp/niscc/NISCC-462660/index.html -
References () http://osvdb.org/33110 - () http://osvdb.org/33110 -
References () http://secunia.com/advisories/24045 - Vendor Advisory () http://secunia.com/advisories/24045 - Vendor Advisory
References () http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&S2ID=14 - () http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&S2ID=14 -
References () http://www.bemacpromotions.com/files/xkpatch462660.zip - URL Repurposed () http://www.bemacpromotions.com/files/xkpatch462660.zip - URL Repurposed
References () http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml - () http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml -
References () http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml - () http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml -
References () http://www.securityfocus.com/bid/22424 - () http://www.securityfocus.com/bid/22424 -
References () http://www.vupen.com/english/advisories/2007/0496 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/0496 - Vendor Advisory

14 Feb 2024, 01:17

Type Values Removed Values Added
References () http://www.bemacpromotions.com/files/xkpatch462660.zip - () http://www.bemacpromotions.com/files/xkpatch462660.zip - URL Repurposed

Information

Published : 2007-02-04 00:28

Updated : 2024-11-21 00:25


NVD link : CVE-2007-0436

Mitre link : CVE-2007-0436

CVE.ORG link : CVE-2007-0436


JSON object : View

Products Affected

barron_mccann

  • x-kryptor_driver
  • xgntr
  • x-kryptor_secure_client
  • install
CWE
CWE-264

Permissions, Privileges, and Access Controls