PT-2011-3560 · Cisco · Cisco Anyconnect Secure Mobility Client+1
Published
2011-06-02
·
Updated
2017-08-29
·
CVE-2011-2039
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco AnyConnect Secure Mobility Client versions prior to 2.3.185
Description
The issue allows remote attackers to execute arbitrary code due to the helper application downloading a client executable file without verifying its authenticity. This is achieved via the
url property to a certain ActiveX control in vpnweb.ocx.Recommendations
For versions prior to 2.3.185, update to version 2.3.185 or later to resolve the issue. As a temporary workaround, consider restricting access to the
vpnweb.ocx ActiveX control to minimize the risk of exploitation.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Anyconnect Secure Mobility Client
Vpnweb.Ocx