Cisco.AnyConnect.VPNAPI.COM.Buffer.Overflow

description-logoDescription

This indicates an attack attempt to exploit a Buffer Overflow vulnerability in Cisco AnyConnect Secure Mobility Client.
The vulnerability, which is located in the Active Template Library (ATL) framework in the VPNAPI COM module, can be exploited through mis-use of the "Unregister" method. It may allow remote attackers to execute arbitrary code in the context of the application using the affected ActiveX control. Failed exploit attempts will likely cause the program to crash,resulting in a denial of service condition.

affected-products-logoAffected Products

Cisco AnyConnect Secure Mobility Client 2.x

Impact logoImpact

System Compromise: Remote attacker can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Refer to the vendor's web site for suggested workaround.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5559

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)