Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users to write to arbitrary files via crafted messages, aka Bug ID CSCus79392.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=37863 | Vendor Advisory |
http://www.securitytracker.com/id/1031930 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cisco
Published: 2015-03-17T01:00:00
Updated: 2015-03-19T15:57:00
Reserved: 2015-01-07T00:00:00
Link: CVE-2015-0663
JSON object: View
NVD Information
Status : Analyzed
Published: 2015-03-17T02:01:49.007
Modified: 2015-10-28T02:17:01.397
Link: CVE-2015-0663
JSON object: View
Redhat Information
No data.
CWE