PT-2017-16115 · Cisco+1 · Cisco Anyconnect Secure Mobility Client+1
Pcchillin
·
Published
2017-02-09
·
Updated
2019-10-03
·
CVE-2017-3813
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco AnyConnect Secure Mobility Client Software for Windows versions prior to 4.4.00243 and 4.3.05017
Description
The issue is due to insufficient implementation of access controls in the Start Before Logon (SBL) module. An unauthenticated, local attacker could exploit this by opening Internet Explorer, allowing them to use the browser with SYSTEM user privileges. This could enable the execution of privileged commands on the targeted system.
Recommendations
For versions prior to 4.4.00243, update to version 4.4.00243 or later.
For versions prior to 4.3.05017, update to version 4.3.05017 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Anyconnect Secure Mobility Client
Internet Explorer