CVE-2023-20178
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.
EPSS 5.37% · 92.1th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | secure_client | 0 |
| Cisco | Cisco Secure Client | 4.9.04043, 4.9.00086, 4.9.01095 |
| cisco | anyconnect_secure_mobility_client | 0 |
Timeline
- Jun 8, 2023 CVE Published
- Jun 8, 2023 PoC Published
- Jun 22, 2023 PoC Published
- Jun 29, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
- Oct 12, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
- Jan 26, 2024 EPSS Score
- Apr 5, 2024 EPSS Score
- May 10, 2024 EPSS Score
- Jul 20, 2024 EPSS Score
- Aug 24, 2024 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-20178 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ssl-dos-uu7mV5p6 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-imp-dos-49GL7rzT advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-csc-privesc-wx4U4Kw advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-priv-esc-Ls2B9t7b advisory