{"api_version":"1","generated_at":"2026-07-23T05:45:16+00:00","cve":"CVE-2011-0926","urls":{"html":"https://cve.report/CVE-2011-0926","api":"https://cve.report/api/cve/CVE-2011-0926.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-0926","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-0926"},"summary":{"title":"CVE-2011-0926","description":"A certain ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) does not properly verify the signature of an unspecified downloaded program, which allows remote attackers to execute arbitrary code by spoofing the CSD installation process, a different vulnerability than CVE-2010-0589.","state":"PUBLISHED","assigner":"cisco","published_at":"2011-02-25 18:00:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securitytracker.com/id?1025118","name":"http://www.securitytracker.com/id?1025118","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Secure Desktop CSDWebInstaller Bugs Let Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/516647/100/0/threaded","name":"http://www.securityfocus.com/archive/1/516647/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-11-091/","name":"http://www.zerodayinitiative.com/advisories/ZDI-11-091/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/8105","name":"http://securityreason.com/securityalert/8105","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Secure Desktop CSDWebInstaller Remote Code Execution Vulnerability - SecurityReason.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/46536","name":"http://www.securityfocus.com/bid/46536","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Secure Desktop ActiveX Control Executable File Arbitrary File Download Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65755","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65755","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0513","name":"http://www.vupen.com/english/advisories/2011/0513","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-0926","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-0926","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"926","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"secure_desktop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:14:26.442Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2011-0513","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0513"},{"name":"cisco-securedesktop-activex-code-execution(65755)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65755"},{"name":"20110223 ZDI-11-091: (0day) Cisco Secure Desktop CSDWebInstaller Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/516647/100/0/threaded"},{"name":"8105","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/8105"},{"name":"1025118","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1025118"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-11-091/"},{"name":"46536","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/46536"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-02-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"A certain ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) does not properly verify the signature of an unspecified downloaded program, which allows remote attackers to execute arbitrary code by spoofing the CSD installation process, a different vulnerability than CVE-2010-0589."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco"},"references":[{"name":"ADV-2011-0513","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0513"},{"name":"cisco-securedesktop-activex-code-execution(65755)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65755"},{"name":"20110223 ZDI-11-091: (0day) Cisco Secure Desktop CSDWebInstaller Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/516647/100/0/threaded"},{"name":"8105","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/8105"},{"name":"1025118","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1025118"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-11-091/"},{"name":"46536","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/46536"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@cisco.com","ID":"CVE-2011-0926","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A certain ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) does not properly verify the signature of an unspecified downloaded program, which allows remote attackers to execute arbitrary code by spoofing the CSD installation process, a different vulnerability than CVE-2010-0589."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2011-0513","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0513"},{"name":"cisco-securedesktop-activex-code-execution(65755)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65755"},{"name":"20110223 ZDI-11-091: (0day) Cisco Secure Desktop CSDWebInstaller Remote Code Execution Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/516647/100/0/threaded"},{"name":"8105","refsource":"SREASON","url":"http://securityreason.com/securityalert/8105"},{"name":"1025118","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1025118"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-11-091/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-11-091/"},{"name":"46536","refsource":"BID","url":"http://www.securityfocus.com/bid/46536"}]}}}},"cveMetadata":{"assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","assignerShortName":"cisco","cveId":"CVE-2011-0926","datePublished":"2011-02-25T17:00:00.000Z","dateReserved":"2011-02-10T00:00:00.000Z","dateUpdated":"2024-08-06T22:14:26.442Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-02-25 18:00:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_desktop:*:*:*:*:*:*:*:*","matchCriteriaId":"F91DD0D2-B573-4FE3-933A-02E8F4D35E56"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"926","Ordinal":"1","Title":"CVE-2011-0926","CVE":"CVE-2011-0926","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"926","Ordinal":"1","NoteData":"A certain ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) does not properly verify the signature of an unspecified downloaded program, which allows remote attackers to execute arbitrary code by spoofing the CSD installation process, a different vulnerability than CVE-2010-0589.","Type":"Description","Title":"CVE-2011-0926"},{"CveYear":"2011","CveId":"926","Ordinal":"2","NoteData":"2011-02-25","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"926","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}