CVE-2012-3052: Medium severity cisco vpn client vulnerability
Published Sep 16, 2012
·Updated
Untrusted search path vulnerability in Cisco VPN Client 5.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka Bug ID CSCua28747.
Affected Software
17 affected components
Cisco VPN Client=5.0
Cisco VPN Client=5.0.01
Cisco VPN Client=5.0.01.0600
Cisco VPN Client=5.0.2
Cisco VPN Client=5.0.02.0090
Cisco VPN Client=5.0.2.0090
Cisco VPN Client=5.0.03.0530
Cisco VPN Client=5.0.03.0560
Cisco VPN Client=5.0.04.0300
Cisco VPN Client=5.0.5
Cisco VPN Client=5.0.05.0290
Cisco VPN Client=5.0.6
Cisco VPN Client=5.0.06.0160
Cisco VPN Client=5.0.7
Cisco VPN Client=5.0.07.0290
Cisco VPN Client=5.0.07.0410
Cisco VPN Client=5.0.07.0440
Event History
Sep 16, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3052?
CVE-2012-3052 is classified as a high severity vulnerability allowing local users to gain elevated privileges.
2
How do I fix CVE-2012-3052?
To fix CVE-2012-3052, upgrade to a patched version of the Cisco VPN Client that addresses this vulnerability.
3
What systems are affected by CVE-2012-3052?
CVE-2012-3052 affects multiple versions of the Cisco VPN Client, including version 5.0 and its variants.
4
What type of vulnerability is CVE-2012-3052?
CVE-2012-3052 is an untrusted search path vulnerability that can allow execution of malicious DLLs.
5
Can CVE-2012-3052 be exploited remotely?
CVE-2012-3052 requires local access to the affected system, so it cannot be exploited remotely.