QID 375534
Date Published: 2021-05-10
QID 375534: Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilities(cisco-sa-anyconnect-code-exec-jR3tWTA6)
Multiple vulnerabilities in the install, uninstall, and upgrade processes of
Cisco AnyConnect Secure Mobility Client for Windows could allow an
authenticated, local attacker to hijack DLL or executable files that are used by the application.
Affected CVEs : CVE-2021-1426,CVE-2021-1427,CVE-2021-1430
Affected Products
Cisco devices if they are running a vulnerable release of Cisco AnyConnect Secure Mobility Client for Windows.
Prior to 4.9.06037
QID Detection Logic (Authenticated):
This checks for vulnerable version of AnyConnect Mobility Client using registry information.
A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges.
To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system.
Customers are advised to refer to cisco-sa-anyconnect-code-exec-jR3tWTA6 for more information.
- cisco-sa-anyconnect-code-exec-jR3tWTA6 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-code-exec-jR3tWTA6
CVEs related to QID 375534
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-anyconnect-code-exec-jR3tWTA6 |
|