CVE-2015-4211

Description

Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCus65862.

Risk Information

Base Score
7.8
MODERATE
Vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.368

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2014-8021,CVE-2015-4211 are affected in Cisco AnyConnect Secure Mobility Client For Windows 3.1Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.1(60)Windows
Cisco AnyConnect Client for Windows Privilege Escalation Vulnerability For Cisco AnyConnect Secure Mobility ClientNCM
CVE-2015-4211NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705981Security Update for Cisco AnyConnect Secure Mobility Client 4.3(2034)
PATCH-338372Cisco AnyConnect Secure Mobility Client (4.10.08029) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234