CVE-2011-2678: Medium severity cisco vpn client vulnerability
The Cisco VPN Client 5.0.7.0240 and 5.0.7.0290 on 64-bit Windows platforms uses weak permissions (NT AUTHORITY\INTERACTIVE:F) for cvpnd.exe, which allows local users to gain privileges by replacing this executable file with an arbitrary program, aka Bug ID CSCtn50645. NOTE: this vulnerability exists because of a CVE-2007-4415 regression.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2678?
CVE-2011-2678 has a medium severity rating due to the potential for local privilege escalation.
How do I fix CVE-2011-2678?
To mitigate CVE-2011-2678, change the permissions of cvpnd.exe to restrict access to trusted users only.
Which versions of Cisco VPN Client are affected by CVE-2011-2678?
CVE-2011-2678 affects Cisco VPN Client versions 5.0.7.0240 and 5.0.7.0290 on 64-bit Windows.
Can local users exploit CVE-2011-2678?
Yes, local users can exploit CVE-2011-2678 to replace cvpnd.exe with arbitrary programs due to weak permissions.
What should I do if I am using an affected version of Cisco VPN Client?
If using an affected version, it is recommended to upgrade to a fixed version or apply the appropriate security patches provided by Cisco.