First published: Tue Oct 12 2010(Updated: )
Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Desktop |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-5008 is classified as a high severity vulnerability.
To mitigate CVE-2009-5008, upgrade to the latest version of Cisco Secure Desktop that addresses this vulnerability.
CVE-2009-5008 affects Cisco Secure Desktop when used with AnyConnect SSL VPN servers.
CVE-2009-5008 is primarily a local privilege escalation vulnerability.
The risk of CVE-2009-5008 includes local users bypassing intended security policy restrictions.