Cisco Secure Desktop CSDWebInstaller Code Execution

Strike ID:
E11-jvp01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
36
Year:
2011

Description

This strike exploits a vulnerability in the Cisco Secure Desktop software suite. Due to improper validation inside and ActiveX control, instantiated upon web based executable downloads arbitrary code may be executed inside user machines when redirected to malicious websites. All versions of Cisco Systems Secured Desktop below 3.5 are affected.

CVE

Bid