CVE-2015-0662: High severity cisco AnyConnect Secure Mobility Client vulnerability
Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to gain privileges via crafted IPC messages that trigger use of root privileges for a software-package installation, aka Bug ID CSCus79385.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0662?
CVE-2015-0662 has a high severity rating due to its potential for local privilege escalation.
How do I fix CVE-2015-0662?
To fix CVE-2015-0662, update Cisco AnyConnect Secure Mobility Client to a version later than 4.0(.00051).
Who is affected by CVE-2015-0662?
CVE-2015-0662 affects local users of Cisco AnyConnect Secure Mobility Client versions up to and including 4.0(.00051).
What kind of attack can CVE-2015-0662 enable?
CVE-2015-0662 can enable local users to gain elevated privileges through crafted IPC messages.
What should I do if I cannot upgrade to fix CVE-2015-0662?
If you cannot upgrade, consider limiting local access to the affected system to mitigate the risks associated with CVE-2015-0662.