Vulnerability Name: | CVE-2007-2229 (CCN-34618) | ||||||||
Assigned: | 2007-06-12 | ||||||||
Published: | 2007-06-12 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | Microsoft Windows Vista uses insecure default permissions for unspecified "local user information data stores" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka "Permissive User Information Store ACLs Information Disclosure Vulnerability." | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-2229 Source: OSVDB Type: UNKNOWN 35344 Source: CCN Type: SA25623 Microsoft Windows Vista User Information Disclosure Source: SECUNIA Type: Vendor Advisory 25623 Source: CCN Type: SECTRACK ID: 1018225 Windows Vista Discloses Sensitive Information to Local Users Source: CCN Type: ASA-2007-257 MS07-032 Vulnerability in Windows Vista Could Allow Information Disclosure (931213) Source: CCN Type: Microsoft Security Bulletin MS07-032 Vulnerability in Windows Vista Could Allow Information Disclosure (931213) Source: CCN Type: OSVDB ID: 35344 Microsoft Windows Vista Local User Information Data Stores Information Disclosure Source: HP Type: UNKNOWN SSRT071438 Source: BID Type: UNKNOWN 24411 Source: CCN Type: BID-24411 Microsoft Windows Vista Permissive User Information Store ACLs Information Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1018225 Source: CERT Type: US Government Resource TA07-163A Source: VUPEN Type: Vendor Advisory ADV-2007-2152 Source: MS Type: UNKNOWN MS07-032 Source: XF Type: UNKNOWN windows-vista-acl-information-disclosure(34618) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1529 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |