CVE-2017-3813 describes a local privilege escalation vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows, affecting versions prior to 4.4.00243 and 4.3.05017. An unauthenticated, local attacker can exploit insufficient access controls to open Internet Explorer with SYSTEM user privileges. This vulnerability carries a CVSSv3 score of 7.8 (High), indicating a low attack complexity and the potential for high impact on confidentiality, integrity, and availability, as it could allow the execution of privileged commands. While not listed on the KEV catalog and with no known Metasploit or Nuclei modules, an ExploitDB entry (EDB-41476) exists, suggesting public exploit code availability, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.00048CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.0.00048:*:*:*:*:*:*:* | ||
4.0.00051CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.0.00051:*:*:*:*:*:*:* | ||
4.0.00052CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.0.00052:*:*:*:*:*:*:* | ||
4.0.00057CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.0.00057:*:*:*:*:*:*:* | ||
4.0.00061CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.0.00061:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.