Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users to write to arbitrary files via crafted messages, aka Bug ID CSCus79392.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=37863 | Vendor Advisory |
http://www.securitytracker.com/id/1031930 |
Configurations
Information
Published : 2015-03-16 19:01
Updated : 2015-10-27 19:17
NVD link : CVE-2015-0663
Mitre link : CVE-2015-0663
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
cisco
- anyconnect_secure_mobility_client