CVE-2020-3153
KEV ransomware PoC ×4massDLL Search Path Hijacking LPE in Cisco AnyConnect Secure Mobility Client for Windows
CISA: Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
CVE-2020-3153 is an uncontrolled search path vulnerability (CWE-427) in the Windows client of Cisco AnyConnect Secure Mobility Client, which mishandles directory paths when running with elevated privileges. An attacker or malware that already has valid credentials and local access on a Windows endpoint can copy malicious files, such as DLLs, into locations loaded by the elevated AnyConnect process. Successful exploitation yields system-level (SYSTEM) privilege execution on the endpoint via DLL preloading or DLL hijacking, making it an effective local privilege escalation step in broader intrusion chains. Any organization running the AnyConnect VPN client on Windows endpoints is potentially affected. The flaw was added to CISA KEV on 2022-10-24 with known ransomware use, and its EPSS of 28.3% (98th percentile) indicates an elevated probability of near-term exploitation, though no public PoC is known.
What to do: Apply the fixed AnyConnect release per Cisco's instructions, as required by CISA's KEV listing, prioritizing Windows endpoints where the client is installed. Inventory your estate for AnyConnect installations and verify client builds are current. Given the known ransomware use, hunt for signs of local DLL planting in writable directories and review privilege-escalation activity on Windows hosts.
| Cisco AnyConnect Secure Mobility Client for Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.
- Affected
- Cisco AnyConnect Secure
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- cisco
- Products
- anyconnect secure mobility client
- Weakness
- CWE-427
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N