Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20084


A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window. This vulnerability is due to a timing issue that occurs between various software components. An attacker could exploit this vulnerability by persuading a user to put a malicious file into a specific folder and then persuading the user to execute the file within a limited time window. A successful exploit could allow the attacker to cause the endpoint software to fail to quarantine the malicious file or kill its process. Note: This vulnerability only applies to deployments that have the Windows Folder Redirection feature enabled.


Published

2023-11-22T17:15:18.317

Last Modified

2024-11-21T07:40:31.210

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.0 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-437
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco secure_endpoint - Yes
Application cisco secure_endpoint 6.0.7 Yes
Application cisco secure_endpoint 6.0.9 Yes
Application cisco secure_endpoint 6.1.5 Yes
Application cisco secure_endpoint 6.1.7 Yes
Application cisco secure_endpoint 6.1.9 Yes
Application cisco secure_endpoint 6.2.1 Yes
Application cisco secure_endpoint 6.2.3 Yes
Application cisco secure_endpoint 6.2.5 Yes
Application cisco secure_endpoint 6.2.9 Yes
Application cisco secure_endpoint 6.2.19 Yes
Application cisco secure_endpoint 6.3.1 Yes
Application cisco secure_endpoint 6.3.3 Yes
Application cisco secure_endpoint 6.3.5 Yes
Application cisco secure_endpoint 6.3.7 Yes
Application cisco secure_endpoint 7.0.5 Yes
Application cisco secure_endpoint 7.1.1 Yes
Application cisco secure_endpoint 7.1.5 Yes
Application cisco secure_endpoint 7.2.3 Yes
Application cisco secure_endpoint 7.2.5 Yes
Application cisco secure_endpoint 7.2.7 Yes
Application cisco secure_endpoint 7.2.11 Yes
Application cisco secure_endpoint 7.2.13 Yes
Application cisco secure_endpoint 7.3.1 Yes
Application cisco secure_endpoint 7.3.3 Yes
Application cisco secure_endpoint 7.3.5 Yes
Application cisco secure_endpoint 7.3.9 Yes
Application cisco secure_endpoint 8.1.3 Yes
Application cisco secure_endpoint 8.1.3.21242 Yes
Application cisco secure_endpoint 8.1.5 Yes
Application cisco secure_endpoint 8.1.5.21322 Yes
Application cisco secure_endpoint 8.1.7 Yes
Application cisco secure_endpoint 8.1.7.21417 Yes
Application cisco secure_endpoint 8.1.7.21512 Yes
Application cisco secure_endpoint_private_cloud < 4.1.0 Yes

References