Cisco bug affects Windows servers
An attacker could take control of a company's security system and run arbitrary code because of a flaw in Cisco Systems Inc.'s Secure Access Control Server (ACS) for Windows servers, the company said in a statement April 23.
The Secure ACS, which controls things such as routers in large networks, firewalls and wireless networks, was found to have a buffer-overflow security flaw after the China-based Network Security (NS) Focus Information Technology team discovered the glitch. Cisco subsequently issued a security advisory, followed by a similar advisory from the NSFocus team.
The buffer-overflow vulnerability can cause service to hang or restart, the NS advisory said. "With carefully crafted data, [an] attacker could run arbitrary code with CSAdmin process privilege on the server."
The hacker could potentially seize control of the Cisco service when it's running on Windows.
"Exploitation of this vulnerability results in denial of service and can potentially result in system administrator access," Cisco said in its advisory.
Cisco is providing repair software and recommended that users install patches or upgrade at their earliest possibility. Patch files are currently available on the company's Web site, and customers can download the fixes from the company's Web site.
Versions of the ACS affected by the vulnerability include 2.6.4, 3.0.3 and 3.1.1.
Viruses
Additional Resources



White Papers & Webcasts
Share our Strength
Download Now
Key Strategies for Managing Data Growth
What are you storage challenges?
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
