CVE-2023-20178
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.
| CWE | CWE-276 |
| Vendor | cisco |
| Product | cisco secure client |
| Ecosystems | |
| Industries | NetworkingTelecommunications |
| Published | Jun 28, 2023 |
| Last Updated | Aug 2, 2024 |
Get instant alerts for cisco cisco secure client
Be the first to know when new high vulnerabilities affecting cisco cisco secure client are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H