The CSDWebInstallerCtrl ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) allows remote attackers to download an unintended Cisco program onto a client machine, and execute this program, by identifying a Cisco program with a Cisco digital signature and then renaming this program to inst.exe, a different vulnerability than CVE-2010-0589 and CVE-2011-0926.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2011/0513 | vdb entry |
http://www.securityfocus.com/bid/46538 | vdb entry |
http://www.securitytracker.com/id?1025118 | vdb entry |
http://www.securityfocus.com/archive/1/516648/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/65754 | vdb entry |
http://securityreason.com/securityalert/8108 | third party advisory |
http://zerodayinitiative.com/advisories/ZDI-11-092/ |