QID 375535
QID 375535: Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilities(cisco-sa-anyconnect-code-exec-jR3tWTA6)
Multiple vulnerabilities in the install, uninstall, and upgrade processes of
Cisco AnyConnect Secure Mobility Client for Windows could allow an
authenticated, local attacker to hijack DLL or executable files that are used by the application.
Affected CVEs : CVE-2021-1428,CVE-2021-1429
Affected Products
Cisco devices if they are running a vulnerable release of Cisco AnyConnect Secure Mobility Client for Windows.
Prior to 4.10.00093
QID Detection Logic (Authenticated):
This checks for vulnerable version of AnyConnect Mobility Client using registry information.
A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges.
To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system.
Customers are advised to refer to cisco-sa-anyconnect-code-exec-jR3tWTA6 for more information.
- cisco-sa-anyconnect-code-exec-jR3tWTA6 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-code-exec-jR3tWTA6
CVEs related to QID 375535
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-anyconnect-code-exec-jR3tWTA6 |
|