CVE-2023-20178
published 2023-06-28CVE-2023-20178: A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could…
PriorityP348high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
5.37%
91.7th percentile
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established.
This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | anyconnect_secure_mobility | — | — |
| cisco | anyconnect_secure_mobility_client | < 4.10.07061 | 4.10.07061 |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows Privilege Escalation Vulnerability
vendor_cisco·2023-06-07·CVSS 7.8
CVE-2023-20178 [HIGH] CWE-276 Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows Privilege Escalation Vulnerability
Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows Privilege Escalation Vulnerability
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established.
This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with
Cisco
Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2023-20178 Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows Privilege Escalation Vulnerability
CVE-2023-20178: Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows Privilege Escalation Vulnerability
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to exec
GHSA
GHSA-6rj9-hcv7-94r5: A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Wind
ghsa_unreviewed·2023-06-28
CVE-2023-20178 [HIGH] CWE-276 GHSA-6rj9-hcv7-94r5: A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Wind
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.
No detection rules found.
No public exploits indexed.
2023-06-28
Published