ZeroHour

CVE-2020-3153

KEV ransomware PoC ×4mass

DLL Search Path Hijacking LPE in Cisco AnyConnect Secure Mobility Client for Windows

CISA: Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

CVSS 3.1
6.5 medium
EPSS
28%p98
Published
()
KEV added
AI analysis

CVE-2020-3153 is an uncontrolled search path vulnerability (CWE-427) in the Windows client of Cisco AnyConnect Secure Mobility Client, which mishandles directory paths when running with elevated privileges. An attacker or malware that already has valid credentials and local access on a Windows endpoint can copy malicious files, such as DLLs, into locations loaded by the elevated AnyConnect process. Successful exploitation yields system-level (SYSTEM) privilege execution on the endpoint via DLL preloading or DLL hijacking, making it an effective local privilege escalation step in broader intrusion chains. Any organization running the AnyConnect VPN client on Windows endpoints is potentially affected. The flaw was added to CISA KEV on 2022-10-24 with known ransomware use, and its EPSS of 28.3% (98th percentile) indicates an elevated probability of near-term exploitation, though no public PoC is known.

What to do: Apply the fixed AnyConnect release per Cisco's instructions, as required by CISA's KEV listing, prioritizing Windows endpoints where the client is installed. Inventory your estate for AnyConnect installations and verify client builds are current. Given the known ransomware use, hunt for signs of local DLL planting in writable directories and review privilege-escalation activity on Windows hosts.

Affected
Cisco AnyConnect Secure Mobility Client for Windows
Estimated exposure
massmillions of enterprise Windows endpoints (AnyConnect is among the most widely deployed corporate VPN clients) — Cisco AnyConnect is one of the most widely deployed enterprise VPN clients worldwide with a user base in the tens of millions, and the flaw affects the Windows client installed on each endpoint, though only endpoints with outdated client…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.

CISA Known Exploited Vulnerability
Affected
Cisco AnyConnect Secure
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
cisco
Products
anyconnect secure mobility client
Weakness
CWE-427
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

In the news