QID 375536

Date Published: 2021-05-10

QID 375536: Cisco AnyConnect Secure Mobility Client for Windows DLL and Executable Hijacking Vulnerabilities(cisco-sa-anyconnect-code-exec-jR3tWTA6)

Multiple vulnerabilities in the install, uninstall, and upgrade processes of
Cisco AnyConnect Secure Mobility Client for Windows could allow an
authenticated, local attacker to hijack DLL or executable files that are used by the application.
Affected CVEs : CVE-2021-1496

Affected Products
Cisco devices if they are running a vulnerable release of Cisco AnyConnect Secure Mobility Client for Windows.
Prior to 4.9.03022

QID Detection Logic (Authenticated):
This checks for vulnerable version of AnyConnect Mobility Client using registry information.

A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges.
To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution

    Customers are advised to refer to cisco-sa-anyconnect-code-exec-jR3tWTA6 for more information.

    CVEs related to QID 375536

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-anyconnect-code-exec-jR3tWTA6 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-code-exec-jR3tWTA6