7.6
CVSSv2

CVE-2011-2039

Published: 02/06/2011 Updated: 29/08/2017
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 765
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) prior to 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote malicious users to execute arbitrary code via the url property to a certain ActiveX control in vpnweb.ocx, aka Bug ID CSCsy00904.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco anyconnect secure mobility client

cisco anyconnect secure mobility client 2.0

cisco anyconnect secure mobility client 2.1

cisco anyconnect secure mobility client 2.2

cisco anyconnect secure mobility client 2.2.128

cisco anyconnect secure mobility client 2.2.133

cisco anyconnect secure mobility client 2.2.136

cisco anyconnect secure mobility client 2.2.140

Exploits

## # $Id: cisco_anyconnect_execrb 12872 2011-06-06 20:15:51Z bannedit $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/cor ...