QID 379028
Date Published: 2023-11-20
QID 379028: Cisco Secure Endpoint (Formerly AMP) Scanning Evasion Vulnerability (cisco-sa-secure-endpoint-dos-RzOgFKnd)
A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window.
Affected Versions:
Secure Endpoint Connector for Windows Prior to 7.5.17
Secure Endpoint Connector for Windows Prior to 8.2.1.21650
QID Detection Logic:
QID checks for the vulnerable version of Secure Endpoint Connector through Registry Key
A successful exploit could allow the attacker to cause the endpoint software to fail to quarantine the malicious file or kill its process.
Solution
Vendor has released fix to address these vulnerabilities. Refer to cisco-sa-secure-endpoint-dos-RzOgFKnd
Vendor References
- cisco-sa-secure-endpoint-dos-RzOgFKnd -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-endpoint-dos-RzOgFKnd
CVEs related to QID 379028
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-secure-endpoint-dos-RzOgFKnd |
|