Cisco AnyConnect Secure Mobility Client Local Privilege Escalation Vulnerability
BID:48077
Info
Cisco AnyConnect Secure Mobility Client Local Privilege Escalation Vulnerability
| Bugtraq ID: | 48077 |
| Class: | Design Error |
| CVE: |
CVE-2011-2041 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 01 2011 12:00AM |
| Updated: | Jun 01 2011 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco AnyConnect Secure Mobility Client 2.3 |
| Not Vulnerable: |
Cisco AnyConnect Secure Mobility Client 2.3.254 |
Discussion
Cisco AnyConnect Secure Mobility Client Local Privilege Escalation Vulnerability
Cisco AnyConnect Secure Mobility Client is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges. Successful exploits will result in the complete compromise of affected computers.
This issue is being tracked by Cisco Bug ID CSCta40556.
Versions prior to AnyConnect Secure Mobility Client 2.3.254 are vulnerable.
Cisco AnyConnect Secure Mobility Client is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges. Successful exploits will result in the complete compromise of affected computers.
This issue is being tracked by Cisco Bug ID CSCta40556.
Versions prior to AnyConnect Secure Mobility Client 2.3.254 are vulnerable.
Exploit / POC
Cisco AnyConnect Secure Mobility Client Local Privilege Escalation Vulnerability
An attacker needs local interactive access to the affected computer.
An attacker needs local interactive access to the affected computer.
Solution / Fix
Cisco AnyConnect Secure Mobility Client Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Cisco AnyConnect Secure Mobility Client Local Privilege Escalation Vulnerability
References:
References: