Cisco VPN Client Privilege Escalation Vulnerability
BID:7599
Info
Cisco VPN Client Privilege Escalation Vulnerability
| Bugtraq ID: | 7599 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 14 2003 12:00AM |
| Updated: | May 14 2003 12:00AM |
| Credit: | Discovery is credited to Nick Staff <[email protected]>. |
| Vulnerable: |
Cisco VPN Client for Windows 3.6.1 Cisco VPN Client for Windows 3.6 (Rel) Cisco VPN Client for Windows 3.6 Cisco VPN Client for Windows 3.5.4 Cisco VPN Client for Windows 3.5.2 B Cisco VPN Client for Windows 3.5.2 Cisco VPN Client for Windows 3.5.1 C Cisco VPN Client for Windows 3.5.1 Cisco VPN Client for Windows 3.1 Cisco VPN Client for Windows 3.0.5 Cisco VPN Client for Windows 3.0 |
| Not Vulnerable: | |
Discussion
Cisco VPN Client Privilege Escalation Vulnerability
The Cisco VPN client could allow a local attacker to escalate their privilege level. When the VPN client is set to start prior to logon, it runs with local System privileges. A third party application can also be set to be executed by the VPN client. Any application, such as explorer.exe, which is configured to be started by the VPN client, will in turn be executed with local System privileges.
A variant of this issue was reported that affects versions of the VPN client which were thought to not be vulnerable.
The Cisco VPN client could allow a local attacker to escalate their privilege level. When the VPN client is set to start prior to logon, it runs with local System privileges. A third party application can also be set to be executed by the VPN client. Any application, such as explorer.exe, which is configured to be started by the VPN client, will in turn be executed with local System privileges.
A variant of this issue was reported that affects versions of the VPN client which were thought to not be vulnerable.
Exploit / POC
Cisco VPN Client Privilege Escalation Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Cisco VPN Client Privilege Escalation Vulnerability
Solution:
Cisco has stated that an option has been added that allows administrators to enable or disable the "Allow launching of third party applications before logon" option. This issue was added under Cisco Bug ID CSCdt76576.
It has been reported that newer versions do not sufficiently address this issue, and it is still possible to launch third party applications through the VPN client.
Solution:
Cisco has stated that an option has been added that allows administrators to enable or disable the "Allow launching of third party applications before logon" option. This issue was added under Cisco Bug ID CSCdt76576.
It has been reported that newer versions do not sufficiently address this issue, and it is still possible to launch third party applications through the VPN client.