First published: Tue Mar 17 2015(Updated: )
The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary files via crafted IPC messages, aka Bug ID CSCus79173.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco AnyConnect Secure | <=4.0\(.00051\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0665 is classified as a high-severity vulnerability due to its potential for unauthorized file manipulation.
To mitigate CVE-2015-0665, users should upgrade to a later version of Cisco AnyConnect Secure Mobility Client that is not impacted by this vulnerability.
The impact of CVE-2015-0665 allows local users to write to arbitrary files, which can compromise the integrity of the system.
CVE-2015-0665 affects users of Cisco AnyConnect Secure Mobility Client version 4.0(.00051) and earlier.
CVE-2015-0665 is a local privilege escalation vulnerability within the Hostscan module of Cisco AnyConnect.