CVE-2011-2041
Summary
| CVE | CVE-2011-2041 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-06-02 20:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows local users to gain privileges via unspecified user-interface interaction, aka Bug ID CSCta40556. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Anyconnect Secure Mobility Client | 2.0 | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 2.1 | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 2.2 | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 2.2.128 | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 2.2.133 | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 2.2.136 | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 2.2.140 | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 2.3 | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 2.3.185 | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
| Operating System | Microsoft | Windows Mobile | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco AnyConnect Secure Mobility Client Lets Remote Users Execute Arbitrary Code and Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| osvdb.org/72716 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Cisco Systems - Redirect to | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Vendor Advisory |
| Cisco AnyConnect Secure Mobility Client Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.