KEVIntel
7.8
CVSS
High

CVE-2020-3433

PUBLISHED

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Exploited in the wild Used in malware Low complexity No user interaction
Vendor
Cisco
Product
Cisco AnyConnect Secure Mobility Client
Published
Aug 17, 2020
EPSS

Description

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.

windows cisa malware ransomware edge metasploit

CVSS scores

CVSS v3.1 7.8 High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2022-10-24 00:00:00 UTC · Source

Used in malware

Recorded 2022-10-24 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Oct 24, 2022

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

anyconnect_lpe

metasploit · Created Unknown

Metasploit module for CVE-2020-3433

goichot/CVE-2020-3433

github · Created 2020-09-25 20:53:48 UTC · 43 stars

PoCs and technical analysis of three vulnerabilities found on Cisco AnyConnect for Windows: CVE-2020-3433, CVE-2020-3434 and CVE-2020-3435

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit