CVE-2016-9192

Description

A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and execute an arbitrary executable file with privileges equivalent to the Microsoft Windows operating system SYSTEM account. More Information: CSCvb68043. Known Affected Releases: 4.3(2039) 4.3(748). Known Fixed Releases: 4.3(4019) 4.4(225).

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
31.083

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2016-6369,CVE-2016-9192 are affected in Cisco AnyConnect Secure Mobility Client For Windows 4.3.01095Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.1.0Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 4.0(64)Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.1(60)Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 4.0(2049)Windows
Vulnerabilities CVE-2015-6305,CVE-2015-6322,CVE-2016-6369,CVE-2016-9192 are affected in Any Connect (Microsoft Store) 3.1.02043Windows
Vulnerabilities CVE-2015-6305,CVE-2015-6322,CVE-2016-6369,CVE-2016-9192 are affected in Any Connect (Microsoft Store) 3.1.05182Windows
Vulnerabilities CVE-2015-6305,CVE-2015-6322,CVE-2016-6369,CVE-2016-9192 are affected in Any Connect (Microsoft Store) 3.1.05187Windows
Vulnerabilities CVE-2015-6305,CVE-2015-6322,CVE-2016-6369,CVE-2016-9192 are affected in Any Connect (Microsoft Store) 3.1.06073Windows
Vulnerabilities CVE-2015-6305,CVE-2015-6322,CVE-2016-6369,CVE-2016-9192 are affected in Any Connect (Microsoft Store) 3.1.07021Windows
Vulnerabilities CVE-2015-6305,CVE-2015-6322,CVE-2016-6369,CVE-2016-9192 are affected in Any Connect (Microsoft Store) 4.0(48)Windows
Vulnerabilities CVE-2015-6305,CVE-2015-6322,CVE-2016-6369,CVE-2016-9192 are affected in Any Connect (Microsoft Store) 4.0.0Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 4.0.00048Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 4.0.00051Windows
Vulnerabilities CVE-2015-6305,CVE-2015-6322,CVE-2016-6369,CVE-2016-9192 are affected in Any Connect (Microsoft Store) 4.1.0Windows
Vulnerabilities CVE-2015-6322,CVE-2016-6369,CVE-2016-9192 are affected in Any Connect (Microsoft Store) 4.1(8)Windows
Vulnerabilities CVE-2016-6369,CVE-2016-9192 are affected in Any Connect (Microsoft Store) 4.2.0Windows
Vulnerabilities CVE-2016-6369,CVE-2016-9192,CVE-2017-3813 are affected in Any Connect (Microsoft Store) 4.2.04039Windows
Vulnerabilities CVE-2016-6369,CVE-2016-9192 are affected in Any Connect (Microsoft Store) 4.3.0Windows
Vulnerabilities CVE-2016-6369,CVE-2016-9192,CVE-2017-3813 are affected in Any Connect (Microsoft Store) 4.3.00748Windows
Vulnerabilities CVE-2016-6369,CVE-2016-9192,CVE-2017-3813 are affected in Any Connect (Microsoft Store) 4.3.01095Windows
Cisco AnyConnect Secure Mobility Client Local Privilege Escalation Vulnerability For Cisco AnyConnect Secure Mobility ClientNCM
CVE-2016-9192NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705981Security Update for Cisco AnyConnect Secure Mobility Client 4.3(2034)
PATCH-338372Cisco AnyConnect Secure Mobility Client (4.10.08029) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234