Vulnerability Bulletins

Cisco AnyConnect Secure Mobility Client Hostscan Path Traversal Vulnerability

   
Affected software Cisco
 
A vulnerability in the inter-process communication (IPC) channel of the Cisco AnyConnect Secure Mobility Client Hostscan module could allow an authenticated, local attacker to write and overwrite arbitrary files with elevated privileges.The vulnerability is due to insufficient path traversal protections in certain IPC commands. An attacker could exploit this vulnerability by sending crafted IPC messages. A successful exploit could allow an attacker to write or overwrite arbitrary files on the

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150314-CVE-2015-0665?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20AnyConnect%20Secure%20Mobility%20Client%20Hostscan%20Path%20