QID 379028

Date Published: 2023-11-20

QID 379028: Cisco Secure Endpoint (Formerly AMP) Scanning Evasion Vulnerability (cisco-sa-secure-endpoint-dos-RzOgFKnd)

A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window.

Affected Versions:
Secure Endpoint Connector for Windows Prior to 7.5.17
Secure Endpoint Connector for Windows Prior to 8.2.1.21650
QID Detection Logic:
QID checks for the vulnerable version of Secure Endpoint Connector through Registry Key

A successful exploit could allow the attacker to cause the endpoint software to fail to quarantine the malicious file or kill its process.

  • CVSS V3 rated as Medium - 4.4 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Refer to cisco-sa-secure-endpoint-dos-RzOgFKnd

    CVEs related to QID 379028

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-secure-endpoint-dos-RzOgFKnd URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-endpoint-dos-RzOgFKnd