<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T11:29:43.565503+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03181</id>
    <title>bdu:2023-03181</title>
    <updated>2026-10-08T11:29:43.689650+00:00</updated>
    <content>bdu:2023-03181</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03181"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0443</id>
    <title>certfr-2023-avi-0443 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Cisco&lt;/span&gt;. Elles permettent à…</title>
    <updated>2026-10-08T11:29:43.689698+00:00</updated>
    <content>certfr-2023-avi-0443</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0443"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-ac-csc-privesc-wx4u4kw</id>
    <title>cisco-sa-ac-csc-privesc-wx4U4Kw — Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows Privilege Esc…</title>
    <updated>2026-10-08T11:29:43.689719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established.

This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.



Attention: Simplifying the Cisco portfolio includes the renaming of security products under one brand: Cisco Secure. For more information, see Meet Cisco Secure ["https://www.cisco.com/c/en/us/products/security/secure-names.html"].</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-ac-csc-privesc-wx4u4kw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-7935</id>
    <title>EUVD-2026-7935</title>
    <updated>2026-10-08T11:29:43.689755+00:00</updated>
    <content>EUVD-2026-7935</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-7935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-20178</id>
    <title>fkie_cve-2023-20178</title>
    <updated>2026-10-08T11:29:43.689769+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established.

 This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-20178"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6rj9-hcv7-94r5</id>
    <title>GHSA-6rj9-hcv7-94r5</title>
    <updated>2026-10-08T11:29:43.689794+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6rj9-hcv7-94r5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-20178</id>
    <title>gsd-2023-20178</title>
    <updated>2026-10-08T11:29:43.689811+00:00</updated>
    <content>gsd-2023-20178</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-20178"/>
  </entry>
</feed>
