PT-2017-16115 · Cisco+1 · Cisco Anyconnect Secure Mobility Client+1

Pcchillin

·

Publicado

2017-02-09

·

Atualizado

2019-10-03

·

CVE-2017-3813

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco AnyConnect Secure Mobility Client Software for Windows versions prior to 4.4.00243 and 4.3.05017
Description The issue is due to insufficient implementation of access controls in the Start Before Logon (SBL) module. An unauthenticated, local attacker could exploit this by opening Internet Explorer, allowing them to use the browser with SYSTEM user privileges. This could enable the execution of privileged commands on the targeted system.
Recommendations For versions prior to 4.4.00243, update to version 4.4.00243 or later. For versions prior to 4.3.05017, update to version 4.3.05017 or later.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-3813

Produtos afetados

Cisco Anyconnect Secure Mobility Client
Internet Explorer