← Back

CVE-2015-6305

nvd nist
Published: Sep 26, 2015Modified: May 6, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConnect Secure Mobility Client 2.0 through 4.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by dbghelp.dll, aka Bug ID CSCuv01279. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4211.

Affected (51)

1 product
Anyconnect Secure Mobility Client
Configuration A
51 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 2.0.0343
Version 2.1.0.148
Version 2.2.0133
Version 2.2.0136
Version 2.2.0140
Version 2.3.0185
Version 2.3.0254
Version 2.3.1003
Version 2.3.2016
Version 2.4.0202
Version 2.4.1012
Version 2.5.0217
Version 2.5.2006
Version 2.5.2010
Version 2.5.2011
Version 2.5.2014
Version 2.5.2017
Version 2.5.2018
Version 2.5.2019
Version 2.5.3041
Version 2.5.3046
Version 2.5.3051
Version 2.5.3054
Version 2.5.3055
Version 2.5_base
Version 3.0.0629
Version 3.0.09231
Version 3.0.09266
Version 3.0.09353
Version 3.0.0
Version 3.0.1047
Version 3.0.2052
Version 3.0.3050
Version 3.0.3054
Version 3.0.4235
Version 3.0.5075
Version 3.0.5080
Version 3.1.02043
Version 3.1.05182
Version 3.1.05187
Version 3.1.06073
Version 3.1.07021
Version 3.1.0
Version 3.1(60)
Version 4.0.00048
Version 4.0.00051
Version 4.0.0
Version 4.0(2049)
Version 4.0(48)
Version 4.0(64)
Version 4.1.0
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (12)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: psirt@cisco.com
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry

Timeline

No history available yet.