Vulnerability record · CVE-2011-2039 · published 2 June 2011
CVE-2011-2039: Cisco AnyConnect helper downloads executable without authenticity check
Cisco · Anyconnect Secure Mobility Client
The helper application in Cisco AnyConnect Secure Mobility Client before 2.3.185 on Windows and Windows Mobile downloads vpndownloader.exe without verifying its authenticity. A remote attacker can supply an arbitrary URL through the url property of an ActiveX control in vpnweb.ocx, causing the client to fetch and run an attacker-controlled executable. Because the flaw undermines the trust boundary of the VPN client itself, it matters for any organization relying on AnyConnect for remote access.
Description
The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a certain ActiveX control in vpnweb.ocx, aka Bug ID CSCsy00904.
AV:N/AC:H/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution in a widely deployed VPN client with a high EPSS score, though the CVSS vector notes high attack complexity and there is no KEV listing.
What it is
The helper application in Cisco AnyConnect Secure Mobility Client before 2.3.185 on Windows and Windows Mobile downloads vpndownloader.exe without verifying its authenticity. A remote attacker can supply an arbitrary URL through the url property of an ActiveX control in vpnweb.ocx, causing the client to fetch and run an attacker-controlled executable. Because the flaw undermines the trust boundary of the VPN client itself, it matters for any organization relying on AnyConnect for remote access.
Impact
An attacker gains arbitrary code execution in the context of the AnyConnect client process on the victim host, which can lead to full system compromise. The VPN client's privileged position makes the host a high-value foothold.
Attack surface
Reached remotely over the network via the url property of the ActiveX control in vpnweb.ocx; the CVSS vector (AV:N/AC:H/Au:N) indicates no authentication is required but exploitation conditions are difficult. The description does not state whether user interaction is needed, so that detail is absent from the record.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is high (0.69959, 99.3rd percentile), indicating elevated predicted likelihood of exploitation activity.
What to do
- Upgrade AnyConnect Secure Mobility Client to 2.3.185 or later on Windows and Windows Mobile; this is the vendor's fixed version per the advisory.
- If immediate upgrade is not possible, restrict or disable the vulnerable ActiveX control (vpnweb.ocx) in browsers and tighten execution controls on endpoints running the client.
- Apply the Cisco security advisory guidance and validate the client download path against a trusted source.
- Limit exposure of VPN client download and web-launch functionality to trusted networks and users where feasible.
- Monitor for unexpected vpndownloader.exe execution or downloads from untrusted URLs on AnyConnect endpoints.
Detection
- Alert on vpndownloader.exe process creation, especially when the parent is a browser or the AnyConnect client and the file originates from an unexpected URL.
- Monitor network connections from AnyConnect endpoints to untrusted or newly seen hosts serving executable content.
- Audit browser and ActiveX control usage of vpnweb.ocx and flag instances where the url property is set to non-Cisco origins.
- Check endpoint file hashes of vpndownloader.exe against known-good Cisco distributions to spot tampered or substituted binaries.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-2039 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-2039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.