First published: Wed Nov 08 2006(Updated: )
Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka "System Policy Evasion".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Desktop | <=3.1.1.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5807 has a medium severity rating due to its ability to allow local users to escape the secure desktop environment.
CVE-2006-5807 affects Cisco Secure Desktop versions up to and including 3.1.1.33.
To fix CVE-2006-5807, upgrade Cisco Secure Desktop to version 3.1.1.45 or later.
The main issue with CVE-2006-5807 is that it allows local users to switch out of the secure desktop environment using certain applications.
There are no official workarounds for CVE-2006-5807, making an upgrade to a secure version the only reliable solution.