Description: A vulnerability has been reported in Cisco Security Agent for Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
The vulnerability is caused due to a boundary error in an unspecified system driver used by the application and can be exploited to cause a buffer overflow via a specially crafted packet sent to port 139/TCP or 445/TCP.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is reported in all versions of Cisco Security Agent for Windows (managed or unmanaged). Please see the vendor's advisory for a list of Cisco products that include the agent.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.
Solution: Apply updates.
-- Managed Cisco Security Agents --
Cisco Security Agent version 4.5.1:
Apply Hotfix 4.5.1.672.
Cisco Security Agent version 5.0:
Apply Hotfix 5.0.0.225.
Cisco Security Agent version 5.1:
Apply Hotfix 5.1.0.106.
Cisco Security Agent version 5.2:
Apply Hotfix 5.2.0.238.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.