CVE-2021-1366
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.
EPSS 0.65% · 71.1th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | anyconnect_secure_mobility_client | 0 |
| Cisco | Cisco AnyConnect Secure Mobility Client | n/a |
| Cisco | N/A |
Exploit Intelligence
- Cisco AnyConnect Posture (HostScan) Local Privilege Escalation: CVE-2021-1366 (github-poc-repo)
- Cisco AnyConnect Posture (HostScan) Local Privilege Escalation: CVE-2021-1366 (github-poc-repo)
- Cisco AnyConnect Posture (HostScan) Local Privilege Escalation: CVE-2021-1366 (github-poc-repo)
- Cisco AnyConnect Posture (HostScan) Local Privilege Escalation: CVE-2021-1366 (github-poc-repo)
- Cisco AnyConnect Posture (HostScan) Local Privilege Escalation: CVE-2021-1366 (github-poc-repo)
- Cisco AnyConnect Posture (HostScan) Local Privilege Escalation: CVE-2021-1366 (github-poc)
- Cisco AnyConnect Posture (HostScan) Local Privilege Escalation: CVE-2021-1366 (github-poc)
- Cisco AnyConnect Posture (HostScan) Local Privilege Escalation: CVE-2021-1366 (github-poc)
- Cisco AnyConnect Posture (HostScan) Local Privilege Escalation: CVE-2021-1366 (github-poc)
- 20210217 Cisco AnyConnect Secure Mobility Client for Windows with VPN Posture (HostScan) Module DLL Hijacking Vulnerability (circl)
Timeline
- Feb 17, 2021 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score