CVE-2023-20084
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window. This vulnerability is due to a timing issue that occurs between various software components. An attacker could exploit this vulnerability by persuading a user to put a malicious file into a specific folder and then persuading the user to execute the file within a limited time window. A successful exploit could allow the attacker to cause the endpoint software to fail to quarantine the malicious file or kill its process. Note: This vulnerability only applies to deployments that have the Windows Folder Redirection feature enabled.
Una vulnerabilidad en el software de endpoint de Cisco Secure Endpoint para Windows podría permitir que un atacante local autenticado evada la protección del endpoint dentro de un período de tiempo limitado. Esta vulnerabilidad se debe a un problema de sincronización que ocurre entre varios componentes de software. Un atacante podría aprovechar esta vulnerabilidad persuadiendo a un usuario para que coloque un archivo malicioso en una carpeta específica y luego persuadiéndolo para que ejecute el archivo dentro de un período de tiempo limitado. Un exploit exitoso podría permitir al atacante hacer que el software del terminal no ponga en cuarentena el archivo malicioso o finalice su proceso. Nota: Esta vulnerabilidad solo se aplica a implementaciones que tienen habilitada la función Redirección de carpetas de Windows.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-27 CVE Reserved
- 2023-11-22 CVE Published
- 2023-11-23 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-437: Incomplete Model of Endpoint Features
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | - | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.0.7 Search vendor "Cisco" for product "Secure Endpoint" and version "6.0.7" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.0.9 Search vendor "Cisco" for product "Secure Endpoint" and version "6.0.9" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.1.5 Search vendor "Cisco" for product "Secure Endpoint" and version "6.1.5" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.1.7 Search vendor "Cisco" for product "Secure Endpoint" and version "6.1.7" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.1.9 Search vendor "Cisco" for product "Secure Endpoint" and version "6.1.9" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.2.1 Search vendor "Cisco" for product "Secure Endpoint" and version "6.2.1" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.2.3 Search vendor "Cisco" for product "Secure Endpoint" and version "6.2.3" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.2.5 Search vendor "Cisco" for product "Secure Endpoint" and version "6.2.5" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.2.9 Search vendor "Cisco" for product "Secure Endpoint" and version "6.2.9" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.2.19 Search vendor "Cisco" for product "Secure Endpoint" and version "6.2.19" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.3.1 Search vendor "Cisco" for product "Secure Endpoint" and version "6.3.1" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.3.3 Search vendor "Cisco" for product "Secure Endpoint" and version "6.3.3" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.3.5 Search vendor "Cisco" for product "Secure Endpoint" and version "6.3.5" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 6.3.7 Search vendor "Cisco" for product "Secure Endpoint" and version "6.3.7" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.0.5 Search vendor "Cisco" for product "Secure Endpoint" and version "7.0.5" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.1.1 Search vendor "Cisco" for product "Secure Endpoint" and version "7.1.1" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.1.5 Search vendor "Cisco" for product "Secure Endpoint" and version "7.1.5" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.2.3 Search vendor "Cisco" for product "Secure Endpoint" and version "7.2.3" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.2.5 Search vendor "Cisco" for product "Secure Endpoint" and version "7.2.5" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.2.7 Search vendor "Cisco" for product "Secure Endpoint" and version "7.2.7" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.2.11 Search vendor "Cisco" for product "Secure Endpoint" and version "7.2.11" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.2.13 Search vendor "Cisco" for product "Secure Endpoint" and version "7.2.13" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.3.1 Search vendor "Cisco" for product "Secure Endpoint" and version "7.3.1" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.3.3 Search vendor "Cisco" for product "Secure Endpoint" and version "7.3.3" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.3.5 Search vendor "Cisco" for product "Secure Endpoint" and version "7.3.5" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 7.3.9 Search vendor "Cisco" for product "Secure Endpoint" and version "7.3.9" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 8.1.3 Search vendor "Cisco" for product "Secure Endpoint" and version "8.1.3" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 8.1.3.21242 Search vendor "Cisco" for product "Secure Endpoint" and version "8.1.3.21242" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 8.1.5 Search vendor "Cisco" for product "Secure Endpoint" and version "8.1.5" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 8.1.5.21322 Search vendor "Cisco" for product "Secure Endpoint" and version "8.1.5.21322" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 8.1.7 Search vendor "Cisco" for product "Secure Endpoint" and version "8.1.7" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 8.1.7.21417 Search vendor "Cisco" for product "Secure Endpoint" and version "8.1.7.21417" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Search vendor "Cisco" for product "Secure Endpoint" | 8.1.7.21512 Search vendor "Cisco" for product "Secure Endpoint" and version "8.1.7.21512" | windows |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Endpoint Private Cloud Search vendor "Cisco" for product "Secure Endpoint Private Cloud" | < 4.1.0 Search vendor "Cisco" for product "Secure Endpoint Private Cloud" and version " < 4.1.0" | - |
Affected
|