CVE-2023-20178 is a privilege escalation vulnerability affecting Cisco AnyConnect Secure Mobility Client and Cisco Secure Client for Windows. It allows a low-privileged, authenticated local attacker to gain SYSTEM privileges due to improper permissions on a temporary update directory. With a CVSS score of 7.8 (HIGH), this vulnerability is easily exploitable with low attack complexity and no user interaction required, leading to full compromise of confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, public exploit code exists, and it has garnered significant community discussion and media coverage, indicating a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.10.07061CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:*:*:*:*:*:windows:*:* | ||
< 5.0.02075CPE matchmatch criteria | cpe:2.3:a:cisco:secure_client:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.