Executive brief
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows allows an authenticated local attacker to copy user-supplied files to system-level directories. This is caused by incorrect handling of directory paths, which can be leveraged for DLL hijacking or pre-loading to achieve privilege escalation.
Affected products
- Cisco AnyConnect Secure Mobility Client for Windows Prior to 4.8.02042
Timeline
- 2020-02-19: disclosed: Initial vendor advisory publication
- 2022-10-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-10-24: exploited: Confirmed exploited in the wild per CISA KEV catalog entry date.