Secure Client (AnyConnect)
CVE-2023-20178: A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Window…
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Cisco Secure Client 4.9 | See the advisory |
| Cisco Secure Client 4.9 | See the advisory |
| Cisco Secure Client 4.9 | See the advisory |
| Cisco Secure Client 4.9 | See the advisory |
| Cisco Secure Client 4.9 | See the advisory |
| Cisco Secure Client 4.9 | See the advisory |
| Cisco Secure Client 4.9 | See the advisory |
| Cisco Secure Client 4.9 | See the advisory |
| Cisco Secure Client 4.9 | See the advisory |
| Cisco Secure Client 4.10 | See the advisory |
| Cisco Secure Client 4.10 | See the advisory |
| Cisco Secure Client 4.10 | See the advisory |
| Cisco Secure Client 4.10 | See the advisory |
| Cisco Secure Client 4.10 | See the advisory |
| Cisco Secure Client 4.10 | See the advisory |
| Cisco Secure Client 4.10 | See the advisory |
| Cisco Secure Client 4.10 | See the advisory |
| Cisco Secure Client 4.10 | See the advisory |
| Cisco Secure Client 4.10 | See the advisory |
| Cisco Secure Client 4.10 | See the advisory |
| Cisco Secure Client 5.0 | See the advisory |
| Cisco Secure Client 5.0 | See the advisory |
| Cisco Secure Client 5.0 | See the advisory |
| Cisco Secure Client 5.0 | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.
Exploitation
The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerability that is described in this advisory.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.