Exploited· due 2022-11-146.5mediumMediumused in ransomware

CVE-2020-3153

Cisco Anyconnect Secure Mobility Client

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.

Exploitation status

  • CISA has confirmed this is being exploited in the wild. That is an observation of real attacks, not a prediction.
  • It is known to have been used in ransomware campaigns.
  • US federal civilian agencies are required to remediate it by 2022-11-14. That deadline does not bind private companies, but it is a reasonable benchmark for how urgently CISA views it.
  • A vendor advisory or patch reference has been published.

Required action

Apply updates per vendor instructions.

CISA’s wording, unedited.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
6.5 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Weakness
CWE-427
Assigned by
psirt@cisco.com

Dates

Published
2020-02-19
Last modified
2026-08-12
Added to KEV
2022-10-24
Remediation due
2022-11-14
Sources
CISA KEV, NVD

Affected products

  • Cisco Anyconnect Secure Mobility Client- 4.8.02042

As listed in the NVD configuration data. Not a statement about your estate.

References