CVE-2009-4118: Low severity cisco vpn client vulnerability
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERRORFAILEDSERVICECONTROLLERCONNECT error, which allows local users to cause a denial of service (service crash and VPN connection loss) via a manual start of cvpnd.exe while the cvpnd service is running.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4118?
CVE-2009-4118 is classified as a denial of service vulnerability that can lead to service crashes and VPN connection loss.
How do I fix CVE-2009-4118?
To mitigate CVE-2009-4118, update your Cisco VPN client to version 5.0.06.0100 or later.
Which versions of Cisco VPN client are affected by CVE-2009-4118?
CVE-2009-4118 affects multiple versions of the Cisco VPN client including versions from 2.0 to 5.0.02.0090.
What type of attack is CVE-2009-4118?
CVE-2009-4118 allows local users to exploit the vulnerability to cause a denial of service.
Is there any public proof of concept for CVE-2009-4118?
There are no public proof of concepts reported for CVE-2009-4118, but the vulnerability can be exploited locally.