>> Cisco VPN Client Graphical User Interface Local Privilege Escalation Vulnerability
Title : Cisco VPN Client Graphical User Interface Local Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2006-1964 CVE ID : CVE-2006-2679
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-05-24
Technical Description
A vulnerability has been identified in Cisco VPN Client for Windows, which could be exploited by malicious users to obtain elevated privileges. This flaw is due to an error in the VPN client dialer (GUI) that fails to properly drop privileges before launching certain dialog boxes, which could be exploited by local attackers to execute arbitrary commands with SYSTEM privileges.