CVE-2015-4211: Cisco AnyConnect Secure Mobility Client

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCus65862.

Affected products

  • Cisco AnyConnect Secure Mobility Client: version 3.1(60) only

Published 2015-06-24. Last modified 2026-06-17.