CVE-2015-0663

Description

Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users to write to arbitrary files via crafted messages, aka Bug ID CSCus79392.

Risk Information

Base Score
7.1
MODERATE
Vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.084

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 4.0Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 4.0(.00051)Windows
Vulnerabilities CVE-2015-0662,CVE-2015-0663,CVE-2015-0664,CVE-2015-0665 are affected in Cisco AnyConnect Secure Mobility Client for Mac 4.0(.00051)Mac
Vulnerabilities CVE-2015-0662,CVE-2015-0663,CVE-2015-0664,CVE-2015-0665 are affected in Cisco AnyConnect Secure Mobility Client for Mac 4.0(.00051)Mac
Cisco AnyConnect Secure Mobility Client Arbitrary File Write Vulnerability For Cisco AnyConnect Secure Mobility ClientNCM
CVE-2015-0663NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705981Security Update for Cisco AnyConnect Secure Mobility Client 4.3(2034)
PATCH-338372Cisco AnyConnect Secure Mobility Client (4.10.08029) (Manual Upload Required)
PATCH-606843Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029
PATCH-606843Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234