CVE-2017-3813: High severity cisco AnyConnect Secure Mobility Client vulnerability
A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user. The vulnerability is due to insufficient implementation of the access controls. An attacker could exploit this vulnerability by opening the Internet Explorer browser. An exploit could allow the attacker to use Internet Explorer with the privileges of the SYSTEM user. This may allow the attacker to execute privileged commands on the targeted system. This vulnerability affects versions prior to released versions 4.4.00243 and later and 4.3.05017 and later. Cisco Bug IDs: CSCvc43976.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco AnyConnect Secure Mobility Client Software for Windows (Start Before Logon (SBL) module)to a version that resolves this vulnerability.Fixed in 4.4.00243 - Upgrade
Upgrade
Cisco AnyConnect Secure Mobility Client Software for Windows (Start Before Logon (SBL) module)to a version that resolves this vulnerability.Fixed in 4.3.05017 - Compensating control
Restrict or monitor use of Internet Explorer initiated by any untrusted/local users until the affected Cisco AnyConnect Start Before Logon (SBL) component is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3813?
CVE-2017-3813 has a critical severity rating due to its potential to allow unauthenticated attackers to execute code with SYSTEM privileges.
How do I fix CVE-2017-3813?
To mitigate CVE-2017-3813, upgrade to the latest version of Cisco AnyConnect Secure Mobility Client available.
Who is affected by CVE-2017-3813?
CVE-2017-3813 affects various versions of Cisco AnyConnect Secure Mobility Client, including versions 4.0.x, 4.1.x, 4.2.x, and 4.3.x.
What could an attacker do with CVE-2017-3813?
An attacker exploiting CVE-2017-3813 could potentially open Internet Explorer with SYSTEM user privileges, leading to further system compromise.
Is there a workaround for CVE-2017-3813?
There are no known workarounds for CVE-2017-3813; the recommended action is to apply the relevant software updates.