CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
25.8%
Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer.
Vendor | Product | Version | CPE |
---|---|---|---|
barron_mccann | install | bms1472 | cpe:2.3:a:barron_mccann:install:bms1472:*:*:*:*:*:*:* |
barron_mccann | x-kryptor_driver | bms1446hrr | cpe:2.3:a:barron_mccann:x-kryptor_driver:bms1446hrr:*:*:*:*:*:*:* |
barron_mccann | x-kryptor_secure_client | * | cpe:2.3:a:barron_mccann:x-kryptor_secure_client:*:*:*:*:*:*:*:* |
barron_mccann | xgntr | bms1351 | cpe:2.3:a:barron_mccann:xgntr:bms1351:*:*:*:*:*:*:* |
jvn.jp/niscc/NISCC-462660/index.html
osvdb.org/33110
secunia.com/advisories/24045
www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&S2ID=14
www.bemacpromotions.com/files/xkpatch462660.zip
www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml
www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml
www.securityfocus.com/bid/22424
www.vupen.com/english/advisories/2007/0496