CVE-2020-3433
KEV ransomware PoC massDLL Hijacking LPE in Cisco AnyConnect Secure Mobility Client for Windows
CISA: Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
Cisco AnyConnect Secure Mobility Client for Windows contains a DLL hijacking flaw (CWE-427) in its interprocess communication (IPC) channel, caused by insufficient validation of resources loaded at run time. An attacker who already has valid credentials on the Windows machine can send a crafted IPC message to the AnyConnect process and coerce it into loading a malicious DLL. Successful exploitation allows arbitrary code execution with SYSTEM privileges, turning a low-privileged local foothold into full administrative control of the endpoint. Any organization running AnyConnect on Windows endpoints is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use, a public proof-of-concept is available, and news reports confirm active exploitation alongside another AnyConnect Windows flaw.
What to do: Upgrade Cisco AnyConnect for Windows to a fixed release per Cisco's security advisory, as required by the CISA KEV required action (apply updates per vendor instructions). Since exploitation requires valid local credentials, limit local logon privileges on endpoints and prioritize patching given known ransomware use. Inventory Windows endpoints for AnyConnect installs and monitor for suspicious DLL loads in the AnyConnect process path.
| Cisco AnyConnect Secure Mobility Client for Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.
- Affected
- Cisco AnyConnect Secure
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- cisco
- Products
- anyconnect secure mobility client
- Weakness
- CWE-427
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H