#VU13408 Improper input validation in Cisco AnyConnect Secure Mobility Client - CVE-2018-0373
Published: June 20, 2018 / Updated: June 21, 2018
Cisco AnyConnect Secure Mobility Client
Cisco Systems, Inc
Description
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyConnect Secure Mobility Client for Windows Desktop due to improper validation of user-supplied data. A local attacker can send a malicious request to the application and cause the system to crash.