CVE-2011-2039: Input Validation
The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a certain ActiveX control in vpnweb.ocx, aka Bug ID CSCsy00904.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2039?
CVE-2011-2039 is classified as a medium severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2011-2039?
To fix CVE-2011-2039, upgrade the Cisco AnyConnect Secure Mobility Client to the latest version available.
Which versions of Cisco AnyConnect are affected by CVE-2011-2039?
CVE-2011-2039 affects Cisco AnyConnect Secure Mobility Client versions prior to 2.3.185.
What type of attack is associated with CVE-2011-2039?
CVE-2011-2039 allows remote attackers to execute arbitrary code by exploiting the lack of authenticity verification in a downloaded executable.
Is CVE-2011-2039 a problem for Windows Mobile users?
Yes, CVE-2011-2039 also affects users on Windows Mobile using the vulnerable version of Cisco AnyConnect.