Description
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subprocess reached through a named pipe, as demonstrated by a UNC share pathname.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| http://www.kb.cert.org/vuls/id/110652 |
|
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T04:26:11.474Z
Reserved: 2015-01-10T00:00:00.000Z
Link: CVE-2015-0925
No data.
Status : Modified
Published: 2015-01-22T14:02:59.803
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-0925
No data.
OpenCVE Enrichment
No data.
Weaknesses