Search



Categories

News

Videos

Underground

Vblogs

Hacking Challenges



Affiliates

Security Distro
LCN Crew

Local Privilege Escalation Vulnerability in Cisco VPN Client

September 4th, 2007 by Patchy
Recently a local privilege escalation vulnerability was found in Cisco’s VPN Client. When Cisco VPN Client is installed, a windows service “Cisco Systems, Inc. VPN Service” is created. The service runs the binary C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe as Local System. Therefore, if you replace cvpnd.exe with another executable, then that program will be ran at startup with root privileges! I fond this vulnerability interesting because it is used at my college to authenticate students when they connect to the wireless network. For that reason, almost every student with a laptop has this software installed, and students are allowed to borrow school laptops from the student center to use the wireless internet. Consequently, anyone could borrow a laptop, gain root access thought the vulnerability, and install a keylogger that sends every keystroke to the attacker’s email! Its been 5 days seen this vulnerability was discovered, and Cisco has already issued a patched version. However, how long will it take for the school to update all their computers? This is just another reason why you should be careful when using school computers!

Video Demonstration: (shows how to gain root access and change the Admin password with this vulnerability)

Discuss Here

Posted in News, Vblog |

4 Responses

  1. Shawn Says:

    love that song for this video
    Local Privilege Escalation Vulnerability in Cisco VPN Client
    whats the name of the song

  2. Patchy Says:

    10 Years - Wasteland

  3. Cdubbed Says:

    That is bad ass….but when you enter the Admin pw are you leaving it blank or typing the pw for the user “bob”?

  4. Patchy Says:

    You can make the password whatever you want.

You must be logged in to leave a comment.