Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Pcchillin

#35129de 56,330
7.8CVSS total
Vulnerabilidades · 1
PT-2017-16115
7.8
2017-02-09
Cisco · Cisco Anyconnect Secure Mobility Client · CVE-2017-3813
**Name of the Vulnerable Software and Affected Versions** Cisco AnyConnect Secure Mobility Client Software for Windows versions prior to 4.4.00243 and 4.3.05017 **Description** The issue is due to insufficient implementation of access controls in the Start Before Logon (SBL) module. An unauthenticated, local attacker could exploit this by opening Internet Explorer, allowing them to use the browser with SYSTEM user privileges. This could enable the execution of privileged commands on the targeted system. **Recommendations** For versions prior to 4.4.00243, update to version 4.4.00243 or later. For versions prior to 4.3.05017, update to version 4.3.05017 or later.