Many organizations worldwide have used Cisco AnyConnect VPNs due to their security and other great features.
Cisco has many products for VPN depending upon the platforms with various versions of Software.
Cisco has released a new security advisory that patches a high-severity privilege escalation vulnerability in Cisco AnyConnect Secure Mobility Client for Windows and Cisco Secure Client Software for Windows.
This vulnerability exists in the client update process of the Cisco AnyConnect Mobility Client and Cisco Secure Client Software for Windows, in which a low-privileged, authenticated user can elevate the privilege to SYSTEM and potentially execute administrative commands.
The Security researcher Filip Dragović who discovered the Arbitrary File Delete vulnerability, released the PoC exploit code.
During the client update process, the vpndownloader.exe process creates a directory in the C:\Windows\temp directory, which checks for files or directories inside it and deletes them.
This functionality is executed with SYSTEM privileges which can be exploited by spawning a cmd process and arbitrarily deleting files from the system.
The following products are affected due to this vulnerability,
Products | Fixed in Version |
Cisco AnyConnect Secure Mobility Client for Windows Software | 4.10MR7 (4.10.07061) |
Cisco Secure Client for Windows Software | 5.0MR2 (5.0.02075) |
Cisco AnyConnect and Cisco Secure Client users are recommended to upgrade to the latest version to prevent attackers from Cisco AnyConnect Flaws.
Manage and secure Your Endpoints Efficiently – Free Download
Cybersecurity in mergers and acquisitions is crucial, as M&A activities represent key inflection points for…
In 2025, cybersecurity trends for CISOs will reflect a landscape that is more dynamic and…
Zero-trust architecture has become essential for securing operations in today’s hyper-connected world, where corporate network…
The Chrome team has officially promoted Chrome 136 to the stable channel for Windows, Mac,…
By fusing agentic AI and contextual threat intelligence, SecAI transforms investigation from a bottleneck into…
According to IBM Security annual research, "Cost of a Data Breach Report 2024", an average…