Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users to write to arbitrary files via crafted messages, aka Bug ID CSCus79392.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=37863 | Vendor Advisory |
http://www.securitytracker.com/id/1031930 |
Configurations
History
No history.
Information
Published : 2015-03-17 02:01
Updated : 2015-10-28 02:17
NVD link : CVE-2015-0663
Mitre link : CVE-2015-0663
CVE.ORG link : CVE-2015-0663
JSON object : View
Products Affected
cisco
- anyconnect_secure_mobility_client
CWE
CWE-264
Permissions, Privileges, and Access Controls