CVE Vulnerabilities

CVE-2016-9192

Published: Dec 14, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and execute an arbitrary executable file with privileges equivalent to the Microsoft Windows operating system SYSTEM account. More Information: CSCvb68043. Known Affected Releases: 4.3(2039) 4.3(748). Known Fixed Releases: 4.3(4019) 4.4(225).

Affected Software

NameVendorStart VersionEnd Version
Anyconnect_secure_mobility_clientCisco3.1(60) (including)3.1(60) (including)
Anyconnect_secure_mobility_clientCisco3.1.0 (including)3.1.0 (including)
Anyconnect_secure_mobility_clientCisco3.1.02043 (including)3.1.02043 (including)
Anyconnect_secure_mobility_clientCisco3.1.05182 (including)3.1.05182 (including)
Anyconnect_secure_mobility_clientCisco3.1.05187 (including)3.1.05187 (including)
Anyconnect_secure_mobility_clientCisco3.1.06073 (including)3.1.06073 (including)
Anyconnect_secure_mobility_clientCisco3.1.07021 (including)3.1.07021 (including)
Anyconnect_secure_mobility_clientCisco4.0(48) (including)4.0(48) (including)
Anyconnect_secure_mobility_clientCisco4.0(64) (including)4.0(64) (including)
Anyconnect_secure_mobility_clientCisco4.0(2049) (including)4.0(2049) (including)
Anyconnect_secure_mobility_clientCisco4.0.0 (including)4.0.0 (including)
Anyconnect_secure_mobility_clientCisco4.0.00048 (including)4.0.00048 (including)
Anyconnect_secure_mobility_clientCisco4.0.00051 (including)4.0.00051 (including)
Anyconnect_secure_mobility_clientCisco4.1(8) (including)4.1(8) (including)
Anyconnect_secure_mobility_clientCisco4.1.0 (including)4.1.0 (including)
Anyconnect_secure_mobility_clientCisco4.2.0 (including)4.2.0 (including)
Anyconnect_secure_mobility_clientCisco4.2.04039 (including)4.2.04039 (including)
Anyconnect_secure_mobility_clientCisco4.3.0 (including)4.3.0 (including)
Anyconnect_secure_mobility_clientCisco4.3.00748 (including)4.3.00748 (including)
Anyconnect_secure_mobility_clientCisco4.3.01095 (including)4.3.01095 (including)

References