First published: Tue Oct 06 2015(Updated: )
Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco VPN Client | =5.0 | |
Cisco VPN Client | =5.0.01 | |
Cisco VPN Client | =5.0.01.0600 | |
Cisco VPN Client | =5.0.2 | |
Cisco VPN Client | =5.0.02.0090 | |
Cisco VPN Client | =5.0.2.0090 | |
Cisco VPN Client | =5.0.03.0530 | |
Cisco VPN Client | =5.0.03.0560 | |
Cisco VPN Client | =5.0.04.0300 | |
Cisco VPN Client | =5.0.5 | |
Cisco VPN Client | =5.0.05.0290 | |
Cisco VPN Client | =5.0.6 | |
Cisco VPN Client | =5.0.06.0160 | |
Cisco VPN Client | =5.0.7 | |
Cisco VPN Client | =5.0.7.0240 | |
Cisco VPN Client | =5.0.7.0290 | |
Cisco VPN Client | =5.0.07.0290 | |
Cisco VPN Client | =5.0.07.0410 | |
Cisco VPN Client | =5.0.07.0440 | |
Cisco VPN Client | =5.0.7.0440 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.