QID 378559

Date Published: 2023-06-08

QID 378559: Cisco AnyConnect Secure Mobility Client Software and Cisco Secure Client Software for Windows Privilege Escalation Vulnerability (cisco-sa-ac-csc-privesc-wx4U4Kw)

A vulnerability in the client update feature of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM.

Affected Products
Cisco AnyConnect Secure Mobility Client for Windows 4.10 and earlier
Cisco Secure Client for Windows Software 5.0

Note:For releases earlier than Release 5.0, Cisco Secure Client for Windows is known as Cisco AnyConnect Secure Mobility Client for Windows.

QID Detection Logic (Authenticated):
This checks for vulnerable version of AnyConnect Mobility Client using registry information.

A successful exploit could allow the attacker to execute code with SYSTEM privileges.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ac-csc-privesc-wx4U4Kw for more information.

    CVEs related to QID 378559

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ac-csc-privesc-wx4U4Kw URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-csc-privesc-wx4U4Kw