2
CVSSv3

CVE-2010-0589

CVSSv4: NA | CVSSv3: 2 | CVSSv2: 9.3 | VMScore: 1000 | EPSS: 0.01572 | KEV: Not Included
Published: 15/04/2010 Updated: 21/11/2024

Vulnerability Summary

The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) prior to 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote malicious users to force the download and execution of arbitrary files via a crafted web page, aka Bug ID CSCta25876.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco secure desktop

cisco secure desktop 3.1

cisco secure desktop 3.1.1

cisco secure desktop 3.1.1.27

cisco secure desktop 3.1.1.33

cisco secure desktop 3.2

cisco secure desktop 3.2.1

cisco secure desktop 3.3

cisco secure desktop 3.4

cisco secure desktop 3.4.1

cisco secure desktop 3.4.2

cisco secure desktop 3.4.2048

Vendor Advisories

Cisco Secure Desktop contains a vulnerable ActiveX control that could allow an attacker to execute arbitrary code with the privileges of the user who is currently logged into the affected system Cisco has released a free software update that addresses this vulnerability There is a workaround that mitigates this vulnerability This advi ...