CVE-2015-0663

medium
Published 2015-03-17 · Modified 2026-05-06
CVSS v3
CVSS v2
6.6
VIR risk
6.6

Description

Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users to write to arbitrary files via crafted messages, aka Bug ID CSCus79392.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/viewAlert.x?alertId=37863

Application impact

VendorProductVersionsFixed
cisco ciscoanyconnect_secure_mobility_client{"endIncluding":"4.0\\(.00051\\)"}

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.