PT-2023-7120 · Cisco · Cisco Secure Endpoint Connector For Windows

Kevin Scheel

·

Published

2023-11-15

·

Updated

2024-01-25

·

CVE-2023-20084

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Secure Endpoint Connector for Windows (affected versions not specified)
Description The issue is related to a timing problem between various software components, which can be exploited by an authenticated, local attacker to evade endpoint protection within a limited time window. This can be achieved by persuading a user to place a malicious file in a specific folder and then execute the file within a limited time frame. A successful exploitation could allow the attacker to cause the endpoint software to fail to quarantine the malicious file or kill its process. The vulnerability is applicable only to deployments with the Windows Folder Redirection feature enabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2023-08147
CVE-2023-20084

Affected Products

Cisco Secure Endpoint Connector For Windows