Vulnerability Description
Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Barron Mccann | Install | bms1472 |
| Barron Mccann | X-Kryptor Driver | bms1446hrr |
| Barron Mccann | X-Kryptor Secure Client | All versions |
| Barron Mccann | Xgntr | bms1351 |
Related Weaknesses (CWE)
References
- http://jvn.jp/niscc/NISCC-462660/index.html
- http://osvdb.org/33110
- http://secunia.com/advisories/24045Vendor Advisory
- http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&S2ID=14
- http://www.bemacpromotions.com/files/xkpatch462660.zipURL Repurposed
- http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml
- http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-2007
- http://www.securityfocus.com/bid/22424
- http://www.vupen.com/english/advisories/2007/0496Vendor Advisory
- http://jvn.jp/niscc/NISCC-462660/index.html
- http://osvdb.org/33110
- http://secunia.com/advisories/24045Vendor Advisory
- http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&S2ID=14
- http://www.bemacpromotions.com/files/xkpatch462660.zipURL Repurposed
- http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml
FAQ
What is CVE-2007-0436?
CVE-2007-0436 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which all...
How severe is CVE-2007-0436?
CVE-2007-0436 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-0436?
Check the references section above for vendor advisories and patch information. Affected products include: Barron Mccann Install, Barron Mccann X-Kryptor Driver, Barron Mccann X-Kryptor Secure Client, Barron Mccann Xgntr.