Cisco AnyConnect Secure Mobility Client Arbitrary File Move Vulnerability
The vulnerability is due to missing source path validation in certain IPC commands. An attacker could exploit this vulnerability by sending crafted IPC messages. An exploit could allow the attacker to move arbitrary files with elevated privileges, which could affect the integrity of the system and cause a denial of service condition.
Cisco has not released software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are not available.
This advisory is available at the following link: http://ift.tt/1MgMgFZ
from Cisco Security Advisory http://ift.tt/1MgMgFZ