#VU50785 Insecure DLL loading in Cisco AnyConnect Secure Mobility Client - CVE-2021-1366
Published: February 17, 2021 / Updated: February 18, 2021
Cisco AnyConnect Secure Mobility Client
Cisco Systems, Inc
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner. A local user can send a crafted IPC message to the AnyConnect process execute arbitrary code on the affected machine with SYSTEM privileges.