← Back

CVE-2021-34788

nvd nist
Published: Oct 6, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.0 / Impact: 5.9
Source: NVD

Description

A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to a race condition in the signature verification process for shared library files that are loaded on an affected device. An attacker could exploit this vulnerability by sending a series of crafted interprocess communication (IPC) messages to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected device with root privileges. To exploit this vulnerability, the attacker must have a valid account on the system.

Affected (1)

1 product
Anyconnect Secure Mobility Client
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 4.10.03104
Running on/withPlatform Versions
Apple
Macos
All versions
Linux
Linux Kernel
All versions

Timeline

No history available yet.