CVE-2007-0436
Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via…
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- barron mccann/install · barron mccann/x-kryptor driver · barron mccann/x-kryptor secure client · barron mccann/xgntr
- Source
- cve@mitre.org
References
- http://jvn.jp/niscc/NISCC-462660/index.html
- http://osvdb.org/33110
- http://secunia.com/advisories/24045Vendor Advisory
- http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&S2ID=14
- http://www.bemacpromotions.com/files/xkpatch462660.zipURL Repurposed
- http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml
- http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml
- http://www.securityfocus.com/bid/22424
- http://www.vupen.com/english/advisories/2007/0496Vendor Advisory
- http://jvn.jp/niscc/NISCC-462660/index.html
- http://osvdb.org/33110
- http://secunia.com/advisories/24045Vendor Advisory
- http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&S2ID=14
- http://www.bemacpromotions.com/files/xkpatch462660.zipURL Repurposed
- http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml
- http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml
- http://www.securityfocus.com/bid/22424
- http://www.vupen.com/english/advisories/2007/0496Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.