Incorrect Privilege Assignment in Cisco AnyConnect Secure Mobility Client - CVE-2021-40124
Published: November 4, 2021
Cisco AnyConnect Secure Mobility Client
Cisco Systems, Inc
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect privilege assignment to scripts executed before user logon in the Network Access Manager (NAM) module. A local administrator can configure a script to be executed before logon and execute arbitrary code with SYSTEM privileges.