← Vulnerability feed

Vulnerability record · CVE-2011-2039 · published 2 June 2011

CVE-2011-2039: Cisco AnyConnect helper downloads executable without authenticity check

Cisco · Anyconnect Secure Mobility Client

The helper application in Cisco AnyConnect Secure Mobility Client before 2.3.185 on Windows and Windows Mobile downloads vpndownloader.exe without verifying its authenticity. A remote attacker can supply an arbitrary URL through the url property of an ActiveX control in vpnweb.ocx, causing the client to fetch and run an attacker-controlled executable. Because the flaw undermines the trust boundary of the VPN client itself, it matters for any organization relying on AnyConnect for remote access.

7.6 CVSS 2.0 High EPSS 70% · top 0.6% CWE-20 · Improper input validation
7.6CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a certain ActiveX control in vpnweb.ocx, aka Bug ID CSCsy00904.

AV:N/AC:H/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution in a widely deployed VPN client with a high EPSS score, though the CVSS vector notes high attack complexity and there is no KEV listing.

What it is

The helper application in Cisco AnyConnect Secure Mobility Client before 2.3.185 on Windows and Windows Mobile downloads vpndownloader.exe without verifying its authenticity. A remote attacker can supply an arbitrary URL through the url property of an ActiveX control in vpnweb.ocx, causing the client to fetch and run an attacker-controlled executable. Because the flaw undermines the trust boundary of the VPN client itself, it matters for any organization relying on AnyConnect for remote access.

Impact

An attacker gains arbitrary code execution in the context of the AnyConnect client process on the victim host, which can lead to full system compromise. The VPN client's privileged position makes the host a high-value foothold.

Attack surface

Reached remotely over the network via the url property of the ActiveX control in vpnweb.ocx; the CVSS vector (AV:N/AC:H/Au:N) indicates no authentication is required but exploitation conditions are difficult. The description does not state whether user interaction is needed, so that detail is absent from the record.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is high (0.69959, 99.3rd percentile), indicating elevated predicted likelihood of exploitation activity.

What to do

  • Upgrade AnyConnect Secure Mobility Client to 2.3.185 or later on Windows and Windows Mobile; this is the vendor's fixed version per the advisory.
  • If immediate upgrade is not possible, restrict or disable the vulnerable ActiveX control (vpnweb.ocx) in browsers and tighten execution controls on endpoints running the client.
  • Apply the Cisco security advisory guidance and validate the client download path against a trusted source.
  • Limit exposure of VPN client download and web-launch functionality to trusted networks and users where feasible.
  • Monitor for unexpected vpndownloader.exe execution or downloads from untrusted URLs on AnyConnect endpoints.

Detection

  • Alert on vpndownloader.exe process creation, especially when the parent is a browser or the AnyConnect client and the file originates from an unexpected URL.
  • Monitor network connections from AnyConnect endpoints to untrusted or newly seen hosts serving executable content.
  • Audit browser and ActiveX control usage of vpnweb.ocx and flag instances where the url property is set to non-Cisco origins.
  • Check endpoint file hashes of vpndownloader.exe against known-good Cisco distributions to spot tampered or substituted binaries.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-2039 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-3433Cisco AnyConnect Windows client DLL hijacking via IPC channelCisco AnyConnect Secure Mobility Client for Windows fails to properly validate resources loaded at run time, allowing a DLL hijacking attack through …KEVEPSS 10%analysed6.5CVE-2020-3153Cisco AnyConnect Windows Installer Path Handling Privilege EscalationThe Cisco AnyConnect Secure Mobility Client for Windows installer mishandles directory paths, letting an authenticated local user copy attacker-suppl…KEVEPSS 28%analysed9.3CVE-2012-3088Cisco anyconnect secure mobility client vulnerabilityCisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe header…EPSS 1.8%9.3CVE-2012-2493Cisco anyconnect secure mobility client improper input validation vulnerabilityThe VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2…EPSS 3.9%9.3CVE-2011-2040Cisco anyconnect secure mobility client improper input validation vulnerabilityThe helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.5.3041, and 3.0.x before 3.0.629, on Linu…EPSS 11%7.8CVE-2023-20178Cisco anyconnect secure mobility client incorrect default permissions vulnerabilityA vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Win…EPSS 5.4%7.8CVE-2021-40124Cisco anyconnect secure mobility client improper privilege management vulnerabilityA vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local…EPSS 0.24%7.8CVE-2021-1426Cisco anyconnect secure mobility client uncontrolled search path element vulnerabilityMultiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authe…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2011-2039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.