CVE-2011-2041: High severity cisco anyconnect secure vulnerability
The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows local users to gain privileges via unspecified user-interface interaction, aka Bug ID CSCta40556.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2041?
CVE-2011-2041 has a high severity rating due to local privilege escalation risks in Cisco AnyConnect Secure Mobility Client.
How do I fix CVE-2011-2041?
To fix CVE-2011-2041, upgrade your Cisco AnyConnect Secure Mobility Client to version 2.3.254 or later.
Which versions of Cisco AnyConnect are affected by CVE-2011-2041?
CVE-2011-2041 affects Cisco AnyConnect Secure Mobility Client versions prior to 2.3.254.
What types of attacks can CVE-2011-2041 enable?
CVE-2011-2041 can enable local users to gain elevated privileges through unspecified user-interface interactions.
Is Cisco AnyConnect Secure Mobility Client vulnerable on Windows Mobile devices due to CVE-2011-2041?
Yes, CVE-2011-2041 also affects Cisco AnyConnect Secure Mobility Client on Windows Mobile devices.