7.2
CVSSv2

CVE-2016-9192

Published: 14/12/2016 Updated: 04/04/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local malicious user to install and execute an arbitrary executable file with privileges equivalent to the Microsoft Windows operating system SYSTEM account. More Information: CSCvb68043. Known Affected Releases: 4.3(2039) 4.3(748). Known Fixed Releases: 4.3(4019) 4.4(225).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco anyconnect secure mobility client 3.1\\(60\\)

cisco anyconnect secure mobility client 4.0\\(64\\)

cisco anyconnect secure mobility client 4.0.00048

cisco anyconnect secure mobility client 3.1.05187

cisco anyconnect secure mobility client 3.1.06073

cisco anyconnect secure mobility client 4.0.00051

cisco anyconnect secure mobility client 4.0\\(48\\)

cisco anyconnect secure mobility client 4.3.00748

cisco anyconnect secure mobility client 4.1\\(8\\)

cisco anyconnect secure mobility client 4.3.01095

cisco anyconnect secure mobility client 4.2.04039

cisco anyconnect secure mobility client 3.1.07021

cisco anyconnect secure mobility client 4.0\\(2049\\)

cisco anyconnect secure mobility client 3.1.05182

cisco anyconnect secure mobility client 3.1.02043

cisco anyconnect secure mobility client 4.1.0

cisco anyconnect secure mobility client 4.0.0

cisco anyconnect secure mobility client 4.2.0

cisco anyconnect secure mobility client 3.1.0

cisco anyconnect secure mobility client 4.3.0

Github Repositories

Proof of concept for CVE-2016-9192.

CVE-2016-9192 Introduction This repository contains the code of a proof of concept that triggers CVE-2016-9192 Licensing All code is licensed under GPLv3, see LICENSE