Exploitation Summary
EIP tracks 2 public exploits for CVE-2011-2039.
PoCs published by Metasploit, bannedit, including Metasploit module exploits/windows/browser/cisco_anyconnect_exec.
AI-analyzed exploit summary This Metasploit module exploits a vulnerability in the Cisco AnyConnect VPN client ActiveX control (vpnweb.ocx) by setting the 'url' property to download and execute a malicious payload (vpndownloader.exe) from an attacker-controlled server.
Description
The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a certain ActiveX control in vpnweb.ocx, aka Bug ID CSCsy00904.
Exploits (2)
This Metasploit module exploits a vulnerability in the Cisco AnyConnect VPN client ActiveX control (vpnweb.ocx) by setting the 'url' property to download and execute a malicious payload (vpndownloader.exe) from an attacker-controlled server.
This Metasploit module exploits a vulnerability in the Cisco AnyConnect VPN client ActiveX control (vpnweb.ocx) by setting the 'url' property to download and execute a malicious file. The exploit serves a crafted HTML page with obfuscated JavaScript to trigger the vulnerability.