Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Gavin Jones

Pesquisador deNGSSecure
#42535de 56,338
6.8CVSS total
Vulnerabilidades · 1
PT-2011-4022
6.8
2011-07-07
Cisco · Cisco Vpn Client · CVE-2011-2678
**Name of the Vulnerable Software and Affected Versions** Cisco VPN Client version 5.0.7.0240 Cisco VPN Client version 5.0.7.0290 **Description** The issue is related to weak permissions for the cvpnd.exe file, which can be exploited by local users to gain privileges. This is achieved by replacing the cvpnd.exe file with an arbitrary program. **Recommendations** For Cisco VPN Client version 5.0.7.0240, update the permissions of cvpnd.exe to prevent local users from replacing the executable. For Cisco VPN Client version 5.0.7.0290, update the permissions of cvpnd.exe to prevent local users from replacing the executable.