CVE Vulnerabilities

CVE-2016-9192

Published: Dec 14, 2016 | Modified: Apr 04, 2017
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and execute an arbitrary executable file with privileges equivalent to the Microsoft Windows operating system SYSTEM account. More Information: CSCvb68043. Known Affected Releases: 4.3(2039) 4.3(748). Known Fixed Releases: 4.3(4019) 4.4(225).

Affected Software

Name Vendor Start Version End Version
Anyconnect_secure_mobility_client Cisco 3.1(60) (including) 3.1(60) (including)
Anyconnect_secure_mobility_client Cisco 3.1.0 (including) 3.1.0 (including)
Anyconnect_secure_mobility_client Cisco 3.1.02043 (including) 3.1.02043 (including)
Anyconnect_secure_mobility_client Cisco 3.1.05182 (including) 3.1.05182 (including)
Anyconnect_secure_mobility_client Cisco 3.1.05187 (including) 3.1.05187 (including)
Anyconnect_secure_mobility_client Cisco 3.1.06073 (including) 3.1.06073 (including)
Anyconnect_secure_mobility_client Cisco 3.1.07021 (including) 3.1.07021 (including)
Anyconnect_secure_mobility_client Cisco 4.0(48) (including) 4.0(48) (including)
Anyconnect_secure_mobility_client Cisco 4.0(64) (including) 4.0(64) (including)
Anyconnect_secure_mobility_client Cisco 4.0(2049) (including) 4.0(2049) (including)
Anyconnect_secure_mobility_client Cisco 4.0.0 (including) 4.0.0 (including)
Anyconnect_secure_mobility_client Cisco 4.0.00048 (including) 4.0.00048 (including)
Anyconnect_secure_mobility_client Cisco 4.0.00051 (including) 4.0.00051 (including)
Anyconnect_secure_mobility_client Cisco 4.1(8) (including) 4.1(8) (including)
Anyconnect_secure_mobility_client Cisco 4.1.0 (including) 4.1.0 (including)
Anyconnect_secure_mobility_client Cisco 4.2.0 (including) 4.2.0 (including)
Anyconnect_secure_mobility_client Cisco 4.2.04039 (including) 4.2.04039 (including)
Anyconnect_secure_mobility_client Cisco 4.3.0 (including) 4.3.0 (including)
Anyconnect_secure_mobility_client Cisco 4.3.00748 (including) 4.3.00748 (including)
Anyconnect_secure_mobility_client Cisco 4.3.01095 (including) 4.3.01095 (including)

References