First published: Thu Jun 02 2011(Updated: )
The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows local users to gain privileges via unspecified user-interface interaction, aka Bug ID CSCta40556.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco AnyConnect | <=2.3.2016 | |
Cisco AnyConnect | =2.0 | |
Cisco AnyConnect | =2.1 | |
Cisco AnyConnect | =2.2 | |
Cisco AnyConnect | =2.2.128 | |
Cisco AnyConnect | =2.2.133 | |
Cisco AnyConnect | =2.2.136 | |
Cisco AnyConnect | =2.2.140 | |
Cisco AnyConnect | =2.3 | |
Cisco AnyConnect | =2.3.185 | |
Microsoft Windows | ||
Windows Mobile Connectivity Tools |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2041 has a high severity rating due to local privilege escalation risks in Cisco AnyConnect Secure Mobility Client.
To fix CVE-2011-2041, upgrade your Cisco AnyConnect Secure Mobility Client to version 2.3.254 or later.
CVE-2011-2041 affects Cisco AnyConnect Secure Mobility Client versions prior to 2.3.254.
CVE-2011-2041 can enable local users to gain elevated privileges through unspecified user-interface interactions.
Yes, CVE-2011-2041 also affects Cisco AnyConnect Secure Mobility Client on Windows Mobile devices.