cisco-sa-anyconnect-nam-priv-yCsRNUGT: Cisco AnyConnect Secure Mobility Client for Windows with Network Access Manager Module Privilege Escalation Vulnerability
A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to incorrect privilege assignment to scripts executed before user logon. An attacker could exploit this vulnerability by configuring a script to be executed before logon. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-nam-priv-yCsRNUGT
Credit
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco AnyConnect vulnerability?
The vulnerability ID for this Cisco AnyConnect vulnerability is cisco-sa-anyconnect-nam-priv-yCsRNUGT.
What is the title of this vulnerability?
The title of this vulnerability is Cisco AnyConnect Secure Mobility Client for Windows with Network Access Manager Module Privilege Escalation Vulnerability.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium.
What software is affected by this vulnerability?
The Cisco AnyConnect Secure Mobility Client for Windows version earlier than 4.10.03104 is affected by this vulnerability.
How can an attacker exploit this vulnerability?
An authenticated, local attacker can exploit this vulnerability by escalating privileges on an affected device.