cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
551
Views
0
Helpful
3
Replies

Cybersecurity Advisory | Cisco AnyConnect for Windows Privilege

sv7
Level 3
Level 3

Hello All,

Received an mail from cisco which states "Cybersecurity Advisory | Cisco AnyConnect for Windows Privilege Escalation Vulnerability" for anyconnect software lower than 4.10 version. Is it impactful for my environment also as i'm using only for Umbrella roaming module. Please find below bug link.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-csc-privesc-wx4U4Kw

3 Replies 3

aaragonb
Cisco Employee
Cisco Employee

Hello,

I would highly recommend upgrading to a fixed version, and going for the 5.0.02075 directly since version 4 will be end of life by next year:
https://support.umbrella.com/hc/en-us/articles/13785492124692-End-of-life-for-AnyConnect-Client-Version-4-x#:~:text=Cisco%20announces%20the%20end%2Dof,end%20on%20March%2031%2C%202024.

 

Hi aaragonb,

Thank you for your reply and would definately would go for an update. Furthermore can you please confirm is it that bug can impact my organisation if i'm using only for roaming module ?.

aaragonb
Cisco Employee
Cisco Employee

Hi,

Yes, your organisation may be vulnerable. This bug impacts the core component of Anyconnect/Secure Client, this component is installed as well even if just the Roaming Module was checked during the installation:

aaragonb_0-1686846605514.png

More details: https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/Cisco-Secure-Client-5/admin/guide/b-cisco-secure-client-admin-guide-5-0/deploy-anyconnect.html#ID-1425-00000111