Cisco Secure Client for Windows DLL Hijacking Vulnerability

Vulnerability

A DLL hijacking vulnerability has been identified in Cisco Secure Client for Windows, specifically when the Secure Firewall Posture Engine is installed. This vulnerability allows an authenticated, local attacker to send a crafted interprocess communication (IPC) message to a Cisco Secure Client process, potentially leading to the execution of arbitrary code with SYSTEM privileges on the affected machine. The vulnerability arises from inadequate validation of resources loaded by the application at runtime. Exploitation requires valid user credentials on the Windows system.

Impact

Successful exploitation allows for arbitrary code execution on the affected machine with SYSTEM privileges.

Remediation

Users are advised to upgrade to Cisco Secure Client version 5.1.8.105 or later. Cisco has released free software updates that address this vulnerability. Customers with service contracts should obtain these updates through their usual channels. For those without service contracts, contact the Cisco Technical Assistance Center (TAC) for assistance.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
10.0
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.