QID 375534

Date Published: 2021-05-10

QID 375534: Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilities(cisco-sa-anyconnect-code-exec-jR3tWTA6)

Multiple vulnerabilities in the install, uninstall, and upgrade processes of
Cisco AnyConnect Secure Mobility Client for Windows could allow an
authenticated, local attacker to hijack DLL or executable files that are used by the application.
Affected CVEs : CVE-2021-1426,CVE-2021-1427,CVE-2021-1430

Affected Products
Cisco devices if they are running a vulnerable release of Cisco AnyConnect Secure Mobility Client for Windows.
Prior to 4.9.06037

QID Detection Logic (Authenticated):
This checks for vulnerable version of AnyConnect Mobility Client using registry information.

A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges.
To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution

    Customers are advised to refer to cisco-sa-anyconnect-code-exec-jR3tWTA6 for more information.

    CVEs related to QID 375534

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-anyconnect-code-exec-jR3tWTA6 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-code-exec-jR3tWTA6