CVE-2015-6305

high
Published 2015-09-26 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.2

Description

Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConnect Secure Mobility Client 2.0 through 4.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by dbghelp.dll, aka Bug ID CSCuv01279. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4211.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
cisco ciscoanyconnect_secure_mobility_client2.0.0343
cisco ciscoanyconnect_secure_mobility_client2.1.0.148
cisco ciscoanyconnect_secure_mobility_client2.2.0133
cisco ciscoanyconnect_secure_mobility_client2.2.0136
cisco ciscoanyconnect_secure_mobility_client2.2.0140
cisco ciscoanyconnect_secure_mobility_client2.3.0185
cisco ciscoanyconnect_secure_mobility_client2.3.0254
cisco ciscoanyconnect_secure_mobility_client2.3.1003
cisco ciscoanyconnect_secure_mobility_client2.3.2016
cisco ciscoanyconnect_secure_mobility_client2.4.0202
cisco ciscoanyconnect_secure_mobility_client2.4.1012
cisco ciscoanyconnect_secure_mobility_client2.5.0217
cisco ciscoanyconnect_secure_mobility_client2.5.2006
cisco ciscoanyconnect_secure_mobility_client2.5.2010
cisco ciscoanyconnect_secure_mobility_client2.5.2011
cisco ciscoanyconnect_secure_mobility_client2.5.2014
cisco ciscoanyconnect_secure_mobility_client2.5.2017
cisco ciscoanyconnect_secure_mobility_client2.5.2018
cisco ciscoanyconnect_secure_mobility_client2.5.2019
cisco ciscoanyconnect_secure_mobility_client2.5.3041
cisco ciscoanyconnect_secure_mobility_client2.5.3046
cisco ciscoanyconnect_secure_mobility_client2.5.3051
cisco ciscoanyconnect_secure_mobility_client2.5.3054
cisco ciscoanyconnect_secure_mobility_client2.5.3055
cisco ciscoanyconnect_secure_mobility_client2.5_base
cisco ciscoanyconnect_secure_mobility_client3.0.0
cisco ciscoanyconnect_secure_mobility_client3.0.0629
cisco ciscoanyconnect_secure_mobility_client3.0.1047
cisco ciscoanyconnect_secure_mobility_client3.0.2052
cisco ciscoanyconnect_secure_mobility_client3.0.3050
cisco ciscoanyconnect_secure_mobility_client3.0.3054
cisco ciscoanyconnect_secure_mobility_client3.0.4235
cisco ciscoanyconnect_secure_mobility_client3.0.5075
cisco ciscoanyconnect_secure_mobility_client3.0.5080
cisco ciscoanyconnect_secure_mobility_client3.0.09231
cisco ciscoanyconnect_secure_mobility_client3.0.09266
cisco ciscoanyconnect_secure_mobility_client3.0.09353
cisco ciscoanyconnect_secure_mobility_client3.1\(60\)
cisco ciscoanyconnect_secure_mobility_client3.1.0
cisco ciscoanyconnect_secure_mobility_client3.1.02043
cisco ciscoanyconnect_secure_mobility_client3.1.05182
cisco ciscoanyconnect_secure_mobility_client3.1.05187
cisco ciscoanyconnect_secure_mobility_client3.1.06073
cisco ciscoanyconnect_secure_mobility_client3.1.07021
cisco ciscoanyconnect_secure_mobility_client4.0\(48\)
cisco ciscoanyconnect_secure_mobility_client4.0\(64\)
cisco ciscoanyconnect_secure_mobility_client4.0\(2049\)
cisco ciscoanyconnect_secure_mobility_client4.0.0
cisco ciscoanyconnect_secure_mobility_client4.0.00048
cisco ciscoanyconnect_secure_mobility_client4.0.00051
cisco ciscoanyconnect_secure_mobility_client4.1.0

References

CWEs

CWE-426

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.