Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Can Huang

Researcher fromWangxuan Institute of Computer Technology, Peking University
#35506of 56,335
7.8Total CVSS
Vulnerabilities · 1
PT-2021-2974
7.8
2021-05-05
Cisco · Cisco Anyconnect Secure Mobility Client · CVE-2021-1426
**Name of the Vulnerable Software and Affected Versions** Cisco AnyConnect Secure Mobility Client for Windows (affected versions not specified) **Description** The issue is related to multiple vulnerabilities in the install, uninstall, and upgrade processes of the software. These vulnerabilities could allow an authenticated, local attacker to hijack DLL or executable files used by the application, potentially executing arbitrary code on an affected device with SYSTEM privileges. The attacker must have valid credentials on the Windows system to exploit these vulnerabilities. Additionally, the vulnerability is associated with the creation of temporary files with insecure permissions during the uninstallation process. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.