CVE-2017-3813: High severity cisco AnyConnect Secure Mobility Client vulnerability

Published Feb 9, 2017
·
Updated

A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user. The vulnerability is due to insufficient implementation of the access controls. An attacker could exploit this vulnerability by opening the Internet Explorer browser. An exploit could allow the attacker to use Internet Explorer with the privileges of the SYSTEM user. This may allow the attacker to execute privileged commands on the targeted system. This vulnerability affects versions prior to released versions 4.4.00243 and later and 4.3.05017 and later. Cisco Bug IDs: CSCvc43976.

Affected Software

25 affected components
cisco AnyConnect Secure Mobility Client=4.0.00048
cisco AnyConnect Secure Mobility Client=4.0.00051
cisco AnyConnect Secure Mobility Client=4.0.00052
cisco AnyConnect Secure Mobility Client=4.0.00057
cisco AnyConnect Secure Mobility Client=4.0.00061
cisco AnyConnect Secure Mobility Client=4.1.00028
cisco AnyConnect Secure Mobility Client=4.1.02011
cisco AnyConnect Secure Mobility Client=4.1.04011
cisco AnyConnect Secure Mobility Client=4.1.06013
cisco AnyConnect Secure Mobility Client=4.1.06020
cisco AnyConnect Secure Mobility Client=4.1.08005
cisco AnyConnect Secure Mobility Client=4.2.00096
cisco AnyConnect Secure Mobility Client=4.2.01022
cisco AnyConnect Secure Mobility Client=4.2.01035
cisco AnyConnect Secure Mobility Client=4.2.02075
cisco AnyConnect Secure Mobility Client=4.2.03013
cisco AnyConnect Secure Mobility Client=4.2.04018
cisco AnyConnect Secure Mobility Client=4.2.04039
cisco AnyConnect Secure Mobility Client=4.2.05015
cisco AnyConnect Secure Mobility Client=4.2.06014
cisco AnyConnect Secure Mobility Client=4.3.00748
cisco AnyConnect Secure Mobility Client=4.3.01095
cisco AnyConnect Secure Mobility Client=4.3.02039
cisco AnyConnect Secure Mobility Client=4.3.03086
cisco AnyConnect Secure Mobility Client=4.3.04027

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Cisco AnyConnect Secure Mobility Client Software for Windows (Start Before Logon (SBL) module) to a version that resolves this vulnerability.

    Fixed in 4.4.00243
  2. Upgrade

    Upgrade Cisco AnyConnect Secure Mobility Client Software for Windows (Start Before Logon (SBL) module) to a version that resolves this vulnerability.

    Fixed in 4.3.05017
  3. Compensating control

    Restrict or monitor use of Internet Explorer initiated by any untrusted/local users until the affected Cisco AnyConnect Start Before Logon (SBL) component is upgraded.

Event History

Feb 9, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-3813?

CVE-2017-3813 has a critical severity rating due to its potential to allow unauthenticated attackers to execute code with SYSTEM privileges.

2

How do I fix CVE-2017-3813?

To mitigate CVE-2017-3813, upgrade to the latest version of Cisco AnyConnect Secure Mobility Client available.

3

Who is affected by CVE-2017-3813?

CVE-2017-3813 affects various versions of Cisco AnyConnect Secure Mobility Client, including versions 4.0.x, 4.1.x, 4.2.x, and 4.3.x.

4

What could an attacker do with CVE-2017-3813?

An attacker exploiting CVE-2017-3813 could potentially open Internet Explorer with SYSTEM user privileges, leading to further system compromise.

5

Is there a workaround for CVE-2017-3813?

There are no known workarounds for CVE-2017-3813; the recommended action is to apply the relevant software updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203