Cisco VPN Client Privilege Escalation Variant Vulnerability
BID:7665
Info
Cisco VPN Client Privilege Escalation Variant Vulnerability
| Bugtraq ID: | 7665 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 22 2003 12:00AM |
| Updated: | May 22 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Nick Staff <[email protected]>. |
| Vulnerable: |
Cisco VPN Client for Windows 3.6.1 Cisco VPN Client for Windows 3.6 (Rel) Cisco VPN Client for Windows 3.6 Cisco VPN Client for Windows 3.5.4 Cisco VPN Client for Windows 3.5.2 B Cisco VPN Client for Windows 3.5.2 Cisco VPN Client for Windows 3.5.1 C Cisco VPN Client for Windows 3.5.1 Cisco VPN Client for Windows 3.1 Cisco VPN Client for Windows 3.0.5 Cisco VPN Client for Windows 3.0 |
| Not Vulnerable: | |
Discussion
Cisco VPN Client Privilege Escalation Variant Vulnerability
The Cisco VPN client could allow a local attacker to escalate their privilege level. When the VPN client is set to start prior to logon, it runs with local System privileges. It is possible to replace a VPN client binary with an arbitrary executable, such as 'explorer.exe'. This will be run prior to logon.
This is a variant of the issue described in BID 7599.
The Cisco VPN client could allow a local attacker to escalate their privilege level. When the VPN client is set to start prior to logon, it runs with local System privileges. It is possible to replace a VPN client binary with an arbitrary executable, such as 'explorer.exe'. This will be run prior to logon.
This is a variant of the issue described in BID 7599.
Exploit / POC
Cisco VPN Client Privilege Escalation Variant Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Cisco VPN Client Privilege Escalation Variant Vulnerability
Solution:
Cisco has confirmed the issue and announced that a fix is under development. Cisco bug CSCeb12179 has been assigned to this issue. This BID will be updated when a fix becomes available.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Cisco has confirmed the issue and announced that a fix is under development. Cisco bug CSCeb12179 has been assigned to this issue. This BID will be updated when a fix becomes available.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.