Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2021-1237 |
CWE-ID | CWE-427 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
Cisco AnyConnect Secure Mobility Client Client/Desktop applications / Other client software |
Vendor |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU49533
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2021-1237
CWE-ID:
CWE-427 - Uncontrolled Search Path Element
Exploit availability: No
DescriptionThe vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to insufficient validation of resources that are loaded by the application at run time in the Network Access Manager and Web Security Agent components. A local user can place a specially crafted .dll file and execute arbitrary code on victim's system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCisco AnyConnect Secure Mobility Client: before 4.9.04043
CPE2.3 External linksQ & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?