First published: Wed Nov 08 2006(Updated: )
The installation of Cisco Secure Desktop (CSD) before 3.1.1.45 uses insecure default permissions (all users full control) for the CSD directory and its parent directory, which allow local users to gain privileges by replacing CSD executables, aka "Local Privilege Escalation".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure | <=3.1.1.33 | |
Cisco Secure | =3.1.1.27 | |
<=3.1.1.33 | ||
=3.1.1.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5808 has a critical severity rating due to its potential for local privilege escalation.
To mitigate CVE-2006-5808, upgrade to Cisco Secure Desktop version 3.1.1.45 or later, ensuring secure permissions are set.
CVE-2006-5808 affects all users of Cisco Secure Desktop versions prior to 3.1.1.45.
CVE-2006-5808 is classified as a local privilege escalation vulnerability.
CVE-2006-5808 is not a remote vulnerability; it requires local access to exploit.