← Back

CVE-2023-20084

nvd nist
Published: Nov 22, 2023Modified: Jun 17, 2026

JSON object

Loading...
4.4
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
Exploitability: 0.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window. This vulnerability is due to a timing issue that occurs between various software components. An attacker could exploit this vulnerability by persuading a user to put a malicious file into a specific folder and then persuading the user to execute the file within a limited time window. A successful exploit could allow the attacker to cause the endpoint software to fail to quarantine the malicious file or kill its process. Note: This vulnerability only applies to deployments that have the Windows Folder Redirection feature enabled.

Affected (35)

2 products
Secure Endpoint
Secure Endpoint Private Cloud
Configuration A
34 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
All versions
Version 6.0.7
Version 6.0.9
Version 6.1.5
Version 6.1.7
Version 6.1.9
Version 6.2.19
Version 6.2.1
Version 6.2.3
Version 6.2.5
Version 6.2.9
Version 6.3.1
Version 6.3.3
Version 6.3.5
Version 6.3.7
Version 7.0.5
Version 7.1.1
Version 7.1.5
Version 7.2.11
Version 7.2.13
Version 7.2.3
Version 7.2.5
Version 7.2.7
Version 7.3.1
Version 7.3.3
Version 7.3.5
Version 7.3.9
Version 8.1.3.21242
Version 8.1.3
Version 8.1.5.21322
Version 8.1.5
Version 8.1.7.21417
Version 8.1.7.21512
Version 8.1.7
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.1.0

Timeline

No history available yet.