QID 316944
Date Published: 2021-04-20
QID 316944: Cisco AnyConnect Secure Mobility Client for Mac OS File Corruption Vulnerability(cisco-sa-anyconnect-mac-dos-36s2y3Lv)
A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS
could allow an authenticated, local attacker to
corrupt the content of any file in the filesystem.
Affected Products
Cisco AnyConnect Secure Mobility Client for Mac OS releases earlier than 4.9.00086.
QID Detection Logic (Authenticated):
This checks for vulnerable version of AnyConnect Mobility Client.
A successful exploit could allow the attacker to corrupt the contents of the file.
If the file is a critical systems file, the exploit could lead to a denial of service condition.
To exploit this vulnerability, the attacker would need to have valid credentials on the system.
Customers are advised to refer to cisco-sa-anyconnect-mac-dos-36s2y3Lv for more information.
- cisco-sa-anyconnect-mac-dos-36s2y3Lv -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-mac-dos-36s2y3Lv
CVEs related to QID 316944
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-anyconnect-mac-dos-36s2y3Lv |
|