Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-20178

Опубликовано: 28 июн. 2023
Источник: nvd
CVSS3: 7.8
EPSS Средний

Описание

A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established.

This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:anyconnect_secure_mobility_client:*:*:*:*:*:windows:*:*
Версия до 4.10.07061 (исключая)
cpe:2.3:a:cisco:secure_client:*:*:*:*:*:windows:*:*
Версия до 5.0.02075 (исключая)

EPSS

Процентиль: 96%
0.27048
Средний

7.8 High

CVSS3

Дефекты

CWE-276
CWE-276

Связанные уязвимости

CVSS3: 7.8
github
больше 2 лет назад

A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.

CVSS3: 7.8
fstec
больше 3 лет назад

Уязвимость средства обеспечения безопасности конечных точек Cisco Secure Client (ранее Cisco AnyConnect Secure Mobility Client) для операционных систем Windows, связанная с недостатками разграничения доступа к временному каталогу, созданному в процессе обновления, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 96%
0.27048
Средний

7.8 High

CVSS3

Дефекты

CWE-276
CWE-276