Access Control Vulnerability in Cisco AnyConnect Software for Windows
CVE-2017-3813
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 9 February 2017
Summary
A vulnerability exists in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows, allowing an unauthenticated local attacker to exploit insufficient access controls. By executing Internet Explorer with elevated SYSTEM privileges, an attacker could potentially execute privileged commands on the host system. This flaw affects specific versions of the software, demanding prompt attention and remediation to ensure security integrity.
Affected Version(s)
Cisco AnyConnect Secure Mobility Client Software for Windows prior to released 4.4.00243 and later and 4.3.05017 and later. Cisco AnyConnect Secure Mobility Client Software for Windows Versions prior to released versions 4.4.00243 and later and 4.3.05017 and later.
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved