CVE-2012-3052

medium
Published 2012-09-16 · Modified 2026-04-29
CVSS v3
CVSS v2
6.9
VIR risk
6.9

Description

Untrusted search path vulnerability in Cisco VPN Client 5.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka Bug ID CSCua28747.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
ciscovpn_client5.0
ciscovpn_client5.0.01
ciscovpn_client5.0.01.0600
ciscovpn_client5.0.2
ciscovpn_client5.0.02.0090
ciscovpn_client5.0.2.0090
ciscovpn_client5.0.03.0530
ciscovpn_client5.0.03.0560
ciscovpn_client5.0.04.0300
ciscovpn_client5.0.5
ciscovpn_client5.0.05.0290
ciscovpn_client5.0.6
ciscovpn_client5.0.06.0160
ciscovpn_client5.0.7
ciscovpn_client5.0.07.0290
ciscovpn_client5.0.07.0410
ciscovpn_client5.0.07.0440

References

Verify integrity in audit chain (admin only). AS-IS.