Skip to main content

Cisco Releases Security Advisory for Secure Client

CVE-2025-20206 could allow an attacker to execute arbitrary code with system privileges

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

CVE-2025-20206 could allow an attacker to execute arbitrary code with system privileges


Threat details

Introduction

Cisco has released a security advisory to address a vulnerability in its Secure Client for Windows. Secure Client is Cisco's endpoint virtual private network (VPN) solution. 

The vulnerability only affects the Windows version of Secure Client, and only affects Secure Clients with the Secure Firewall Posture Engine module installed.


Remediation advice

Affected organisations are encouraged to review Cisco Security Advisory cisco-sa-secure-dll-injection-AOyzEqSg and apply the relevant updates as soon as practicable.



Last edited: 6 March 2025 2:11 pm