#VU57124 Time-of-check Time-of-use (TOCTOU) Race Condition in Cisco AnyConnect Secure Mobility Client - CVE-2021-34788
Published: October 7, 2021
Cisco AnyConnect Secure Mobility Client
Cisco Systems, Inc
Description
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to a race condition in the signature verification process for shared library files that are loaded on an affected device. A local user can send a series of crafted interprocess communication (IPC) messages and execute arbitrary code on the target device with root privileges.