Access Control Vulnerability in Cisco AnyConnect Software for Windows
CVE-2017-3813
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 9 February 2017
What is CVE-2017-3813?
A vulnerability exists in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows, allowing an unauthenticated local attacker to exploit insufficient access controls. By executing Internet Explorer with elevated SYSTEM privileges, an attacker could potentially execute privileged commands on the host system. This flaw affects specific versions of the software, demanding prompt attention and remediation to ensure security integrity.
Affected Version(s)
Cisco AnyConnect Secure Mobility Client Software for Windows prior to released 4.4.00243 and later and 4.3.05017 and later. Cisco AnyConnect Secure Mobility Client Software for Windows Versions prior to released versions 4.4.00243 and later and 4.3.05017 and later.