Cisco AnyConnect Secure Mobility Client is prone to multiple vulnerabilities that allow attackers to run an arbitrary executable. This issue affects the VPN Downloader component.
An attacker can exploit this issue by using social engineering techniques to coerce unsuspecting users to download and execute arbitrary applications.
Successful exploits will allow an attacker to execute arbitrary code in the context of the user running the web browser. Failed exploit attempts will likely result in a denial-of-service condition.
These issues are tracked by Cisco Bug IDs CSCtw47523 and CSCty45925.
Vendor Status:
Currently ,the vendor didnt issued any updated vulnerability.