9.3
CVSSv2

CVE-2010-0589

Published: 15/04/2010 Updated: 17/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) prior to 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote malicious users to force the download and execution of arbitrary files via a crafted web page, aka Bug ID CSCta25876.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco secure desktop 3.1.1

cisco secure desktop 3.2

cisco secure desktop

cisco secure desktop 3.1.1.27

cisco secure desktop 3.4

cisco secure desktop 3.4.1

cisco secure desktop 3.1.1.33

cisco secure desktop 3.1

cisco secure desktop 3.4.2

cisco secure desktop 3.4.2048

cisco secure desktop 3.2.1

cisco secure desktop 3.3

Vendor Advisories

Cisco Secure Desktop contains a vulnerable ActiveX control that could allow an attacker to execute arbitrary code with the privileges of the user who is currently logged into the affected system Cisco has released a free software update that addresses this vulnerability There is a workaround that mitigates this vulnerability This advi ...