Cisco Secure Desktop CSDWebInstaller ActiveX Multiple Vulnerabilities
Last Update Date:
1 Mar 2011 17:04
Release Date:
1 Mar 2011
6555
Views
RISK: High Risk
TYPE: Security software and application - Security Software & Appliance
Two vulnerabilities have been identified in Cisco Secure Desktop, which could be exploited by remote attackers to compromise a vulnerable system.
- An error in the "CSDWebInstallerCtrl" ActiveX control (CSDWebInstaller.ocx) when handling a Cisco-signed executable file named "inst.exe", which could allow attackers to exploit certain vulnerabilities in signed executable files.
- An error in the "CSDWebInstallerCtrl" ActiveX control (CSDWebInstaller.ocx) that does not properly verify the digital signature of an executable file that is downloaded and executed, which could allow attackers to execute arbitrary code by tricking a user into visiting a malicious web page.
Impact
- Remote Code Execution
System / Technologies affected
- Cisco Secure Desktop versions 3.x
Solutions
- There is no patch available for this vulnerability currently.
Vulnerability Identifier
Source
Related Link
Share with