CVE-2012-4655: Input Validation
The WebLaunch feature in Cisco Secure Desktop before 3.6.6020 does not properly validate binaries that are received by the downloader process, which allows remote attackers to execute arbitrary code via vectors involving (1) ActiveX or (2) Java components, aka Bug IDs CSCtz76128 and CSCtz78204.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4655?
CVE-2012-4655 has been assigned a moderate severity level due to its potential to allow remote code execution.
How do I fix CVE-2012-4655?
To mitigate CVE-2012-4655, update Cisco Secure Desktop to the latest version provided by Cisco.
What versions are affected by CVE-2012-4655?
CVE-2012-4655 affects Cisco Secure Desktop versions before 3.6.6020.
What type of vulnerability is CVE-2012-4655?
CVE-2012-4655 is a remote code execution vulnerability caused by improper validation of binaries in the WebLaunch feature.
Who discovered CVE-2012-4655?
CVE-2012-4655 was identified through internal Cisco security assessments and reported as Bug IDs CSCtz76128 and CSCtz78204.