CVE-2015-0664
published 2015-03-18CVE-2015-0664: The IPC channel in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary userspace memory locations, and…
PriorityP421medium4.3CVSS 2.0
AVLACLAuSCPIPAP
EPSS
0.32%
23.6th percentile
The IPC channel in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary userspace memory locations, and consequently gain privileges, via crafted messages, aka Bug ID CSCus79195.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | anyconnect_secure_mobility_client | <= 4.0\(.00051\) | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jf8j-hmx6-pcgf: The IPC channel in Cisco AnyConnect Secure Mobility Client 4
ghsa_unreviewed·2022-05-17
CVE-2015-0664 [MEDIUM] CWE-20 GHSA-jf8j-hmx6-pcgf: The IPC channel in Cisco AnyConnect Secure Mobility Client 4
The IPC channel in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary userspace memory locations, and consequently gain privileges, via crafted messages, aka Bug ID CSCus79195.
Cisco
Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability
vendor_cisco·2015-03-14·CVSS 4.3
CVE-2015-0664 [MEDIUM] CWE-20 Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability
Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability
A vulnerability in the inter-process communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to execute arbitrary code.
The vulnerability is due to a lack of input sanitization of certain IPC commands. An attacker could exploit this vulnerability by sending crafted messages over the IPC channel. A successful exploit could allow the attacker to write to arbitrary user space memory. This could allow an attacker to execute arbitrary code, disclose information, or crash the AnyConnect application.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker must auth
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-03-18
Published