Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation file, aka Bug ID CSCuv11947.
https://www.securify.nl/advisory/SFY20150701/cisco_anyconnect_elevation_%20of_privileges_via_dmg_install_script.html
http://www.securitytracker.com/id/1033656
http://seclists.org/fulldisclosure/2015/Sep/86
http://www.securityfocus.com/archive/1/536534/100/0/threaded
http://tools.cisco.com/security/center/viewAlert.x?alertId=41135
Source: Mitre, NVD
Published: 2015-09-26
Updated: 2025-04-12
Base Score: 7.2
Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.05958