Cisco VPN Client for Windows GUI privilege escalation
| cisco-winvpn-privilege-escalation (26632) |
Description:
The Cisco VPN Client for Windows could allow a local attacker to gain elevated privileges on the system, caused by an unspecified vulnerability in the Cisco VPN Client for Windows GUI (VPN client dialer). An attacker with valid authentication credentials could exploit this vulnerability to obtain LocalSystem privileges on an affected system.
Consequences:
Gain Privileges
Remedy:
Upgrade to the latest version of the Cisco VPN Client for Windows (4.8.01.0300 or later), as listed in Cisco Security Advisory cisco-sa-20060524-vpnclient. See References.
References:
- cisco-sa-20060524-vpnclient: Cisco Security Advisory: Windows VPN Client Local Privilege Escalation Vulnerability.
- BID-18094: Cisco VPN Client Local Privilege Escalation Vulnerability
- CVE-2006-2679: Unspecified vulnerability in the VPN Client for Windows Graphical User Interface (GUI) (aka the VPN client dialer) in Cisco VPN Client for Windows 4.8.00.* and earlier, except for 4.7.00.0533, allows local authenticated, interactive users to gain privileges, possibly due to privileges of dialog boxes, aka bug ID CSCsd79265.
- OSVDB ID: 25888: Cisco VPN Client Dialer Local Privilege Escalation
- SA20261: Cisco VPN Client Privilege Escalation Vulnerability
- SECTRACK ID: 1016156: Cisco VPN Client for Windows Lets Local Users Gain Elevated Privileges
- VUPEN/ADV-2006-1964: Cisco VPN Client Graphical User Interface Local Privilege Escalation Vulnerability
Platforms Affected:
- Cisco VPN Client 2.0
- Cisco VPN Client 3.0
- Cisco VPN Client 3.0.5
- Cisco VPN Client 3.1
- Cisco VPN Client 3.5.1
- Cisco VPN Client 3.5.1C
- Cisco VPN Client 3.5.2
- Cisco VPN Client 4.7.00.0000
- Cisco VPN Client 4.8.00.0000
Reported:
May 24, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
