CVE-2023-20178
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.
EPSS 27.74% · 96.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | secure_client | 0 |
| Cisco | Cisco Secure Client | 4.9.04043, 4.9.00086, 4.9.01095 |
| cisco | anyconnect_secure_mobility_client | 0 |
Exploit Intelligence
- Wh04m1001/CVE-2023-20178 (github-poc-repo)
- Wh04m1001/CVE-2023-20178 (github-poc-repo)
- Wh04m1001/CVE-2023-20178 (github-poc-repo)
- Wh04m1001/CVE-2023-20178 (github-poc-repo)
- Wh04m1001/CVE-2023-20178 (github-poc-repo)
- Wh04m1001/CVE-2023-20178 (github-poc)
- Wh04m1001/CVE-2023-20178 (github-poc)
- Wh04m1001/CVE-2023-20178 (github-poc)
- Wh04m1001/CVE-2023-20178 (github-poc)
- Wh04m1001/CVE-2023-20178 (github-poc)
…and 6 more exploits
Timeline
- Jun 8, 2023 CVE Published
- Jun 8, 2023 PoC Published
- Jun 22, 2023 PoC Published
- Jun 29, 2023 EPSS Score
- Aug 3, 2023 EPSS Score
- Oct 12, 2023 EPSS Score
- Nov 16, 2023 EPSS Score
- Jan 25, 2024 EPSS Score
- Feb 29, 2024 EPSS Score
- May 9, 2024 EPSS Score
- Jun 13, 2024 EPSS Score
- Aug 22, 2024 EPSS Score
References
- cisco-sa-ac-csc-privesc-wx4U4Kw url
- https://nvd.nist.gov/vuln/detail/CVE-2023-20178 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ssl-dos-uu7mV5p6 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-priv-esc-Ls2B9t7b advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-imp-dos-49GL7rzT advisory