First published: Thu Apr 11 2013(Updated: )
Heap-based buffer overflow in ciscod.exe in the Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) allows local users to gain privileges via unspecified vectors, aka Bug ID CSCud14143.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco AnyConnect Secure Mobility Client | ||
Cisco AnyConnect Secure Mobility Client | =2.0 | |
Cisco AnyConnect Secure Mobility Client | =2.1 | |
Cisco AnyConnect Secure Mobility Client | =2.2 | |
Cisco AnyConnect Secure Mobility Client | =2.2.128 | |
Cisco AnyConnect Secure Mobility Client | =2.2.133 | |
Cisco AnyConnect Secure Mobility Client | =2.2.136 | |
Cisco AnyConnect Secure Mobility Client | =2.2.140 | |
Cisco AnyConnect Secure Mobility Client | =2.3 | |
Cisco AnyConnect Secure Mobility Client | =2.3.185 | |
Cisco AnyConnect Secure Mobility Client | =2.3.254 | |
Cisco AnyConnect Secure Mobility Client | =2.3.2016 | |
Cisco AnyConnect Secure Mobility Client | =2.4 | |
cisco AnyConnect Secure Mobility Client symbian os | =2.4 | |
Cisco AnyConnect Secure Mobility Client | =2.4.0202 | |
Cisco AnyConnect Secure Mobility Client | =2.4.1012 | |
cisco AnyConnect Secure Mobility Client iphone os | =2.4.4004 | |
cisco AnyConnect Secure Mobility Client iphone os | =2.4.4014 | |
cisco AnyConnect Secure Mobility Client symbian os | =2.4.5004 | |
cisco AnyConnect Secure Mobility Client android | =2.4.7030 | |
cisco AnyConnect Secure Mobility Client android | =2.4.7073 | |
Cisco AnyConnect Secure Mobility Client | =2.5 | |
Cisco AnyConnect Secure Mobility Client | =2.5.0217 | |
Cisco AnyConnect Secure Mobility Client | =2.5.1025 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2001 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2006 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2010 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2011 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2014 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2017 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2018 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2019 | |
Cisco AnyConnect Secure Mobility Client | =2.5.3041 | |
Cisco AnyConnect Secure Mobility Client | =2.5.3046 | |
Cisco AnyConnect Secure Mobility Client | =2.5.3051 | |
Cisco AnyConnect Secure Mobility Client | =2.5.3054 | |
Cisco AnyConnect Secure Mobility Client | =2.5.3055 | |
cisco AnyConnect Secure Mobility Client iphone os | =2.5.5112 | |
cisco AnyConnect Secure Mobility Client android | =2.5.5116 | |
cisco AnyConnect Secure Mobility Client android | =2.5.5118 | |
cisco AnyConnect Secure Mobility Client android | =2.5.5125 | |
cisco AnyConnect Secure Mobility Client iphone os | =2.5.5130 | |
cisco AnyConnect Secure Mobility Client android | =2.5.5131 | |
Cisco AnyConnect Secure Mobility Client | =2.5.6005 | |
Cisco AnyConnect Secure Mobility Client | =3.0 | |
Cisco AnyConnect Secure Mobility Client | =3.0 | |
Cisco AnyConnect Secure Mobility Client | =3.0.0629 | |
Cisco AnyConnect Secure Mobility Client | =3.0.1047 | |
Cisco AnyConnect Secure Mobility Client | =3.0.2052 | |
Cisco AnyConnect Secure Mobility Client | =3.0.3050 | |
Cisco AnyConnect Secure Mobility Client | =3.0.3054 | |
Cisco AnyConnect Secure Mobility Client | =3.0.4235 | |
Cisco AnyConnect Secure Mobility Client | =3.0.5075 | |
Cisco AnyConnect Secure Mobility Client | =3.0.5080 | |
Cisco AnyConnect Secure Mobility Client | =3.0.07059 | |
Cisco AnyConnect Secure Mobility Client | =3.0.08057 | |
Cisco AnyConnect Secure Mobility Client | =3.0.08057 | |
Cisco AnyConnect Secure Mobility Client | =3.0.08066 | |
Cisco AnyConnect Secure Mobility Client | =3.1.0 | |
Cisco AnyConnect Secure Mobility Client | =3.1.00495 | |
Cisco AnyConnect Secure Mobility Client | =3.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1173 has a high severity rating as it allows local users to exploit a heap-based buffer overflow for privilege escalation.
To fix CVE-2013-1173, update your Cisco AnyConnect Secure Mobility Client to the latest version available.
CVE-2013-1173 affects multiple versions of Cisco AnyConnect Secure Mobility Client, including versions 2.0 through 3.2.0.
No, CVE-2013-1173 requires local access to the system to execute the exploit.
CVE-2013-1173 is classified as a heap-based buffer overflow vulnerability.