CVE-2023-20178
Błąd w procesie aktualizacji Cisco AnyConnect umożliwia lokalnemu atakującemu eskalację uprawnień do SYSTEM.
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 5.4% |
| Opublikowano (NVD) | 2023-06-28 15:15:09 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:17:22 UTC |