Privilege Escalation via Crafted INF File in Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows (CSCus65862)

Privilege Escalation via Crafted INF File in Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows (CSCus65862)

CVE-2015-4211 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCus65862.

Learn more about our User Device Pen Test.