CVE-2016-6369: Cisco AnyConnect Secure Mobility Client

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464.

Affected products

  • Cisco AnyConnect Secure Mobility Client: version 2.0.0343 only; version 2.1.0148 only; version 2.2.0133 only; version 2.2.0136 only; version 2.2.0140 only; version 2.3.0185 only; …

Published 2016-08-25. Last modified 2026-06-17.