vendor:
Cisco AnyConnect Secure Mobility Client
by:
@Pcchillin
7.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Cisco AnyConnect Secure Mobility Client
Affected Version From: 4.3.04027 and earlier
Affected Version To: 4.3.4028
Patch Exists: YES
Related CWE: CVE-2017-3813
CPE: a:cisco:anyconnect_secure_mobility_client:4.3.04028
Metasploit:
https://www.rapid7.com/db/vulnerabilities/cisco-anyconnect-cve-2017-3813/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2015-3813/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-3813/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2015-3813/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2015-3813/
Platforms Tested: Windows 10
2017
Cisco AnyConnect Start Before Logon (SBL) local privilege escalation
The exploit allows an attacker to run CMD.EXE with system privileges by manipulating the Cisco AnyConnect application from the logon screen. It also allows running scripts from a USB flash drive.
Mitigation:
Upgrade to version 4.3.04029 or later.