QID 378559
Date Published: 2023-06-08
QID 378559: Cisco AnyConnect Secure Mobility Client Software and Cisco Secure Client Software for Windows Privilege Escalation Vulnerability (cisco-sa-ac-csc-privesc-wx4U4Kw)
A vulnerability in the client update feature of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM.
Affected Products
Cisco AnyConnect Secure Mobility Client for Windows 4.10 and earlier
Cisco Secure Client for Windows Software 5.0
Note:For releases earlier than Release 5.0, Cisco Secure Client for Windows is known as Cisco AnyConnect Secure Mobility Client for Windows.
QID Detection Logic (Authenticated):
This checks for vulnerable version of AnyConnect Mobility Client using registry information.
A successful exploit could allow the attacker to execute code with SYSTEM privileges.
Customers are advised to refer to cisco-sa-ac-csc-privesc-wx4U4Kw for more information.
- cisco-sa-ac-csc-privesc-wx4U4Kw -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-csc-privesc-wx4U4Kw
CVEs related to QID 378559
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ac-csc-privesc-wx4U4Kw |
|