CVE-2021-1366
Last modified
CVE-2021-1366 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to insufficient validation of resources that are loaded by the application at run time. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Anyconnect Secure Mobility Client | < 4.9.05042 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-1366?
How severe is CVE-2021-1366?
How do I fix CVE-2021-1366?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-1360Multiple vulnerabilities in the web-based management interfa…7.2
- CVE-2021-1361A vulnerability in the implementation of an internal file ma…9.1
- CVE-2021-1362A vulnerability in the SOAP API endpoint of Cisco Unified Co…8.8
- CVE-2021-1363Multiple vulnerabilities in the web-based management interfa…8.1
- CVE-2021-1364Multiple vulnerabilities in Cisco Unified Communications Man…4.9
- CVE-2021-1365Multiple vulnerabilities in the web-based management interfa…8.1
- CVE-2021-1367A vulnerability in the Protocol Independent Multicast (PIM) …4.3
- CVE-2021-1368A vulnerability in the Unidirectional Link Detection (UDLD) …8.8
- CVE-2021-1369A vulnerability in the REST API of Cisco Firepower Device Ma…5.4
- CVE-2021-1370A vulnerability in a CLI command of Cisco IOS XR Software fo…7.8
- CVE-2021-1371A vulnerability in the role-based access control of Cisco IO…6.6
- CVE-2021-1372A vulnerability in Cisco Webex Meetings Desktop App and Webe…5.5
Are you affected by CVE-2021-1366?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
