ZeroHour
Security Affairspublished ()ingested @securityaffairs

Two flaws in Cisco AnyConnect Secure Mobility client for Windows actively exploited

criticalExploit / PoC exploited in the wildimportance 60CVE-2020-3153CVE-2020-3433

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3153
DLL Search Path Hijacking LPE in Cisco AnyConnect Secure Mobility Client for Windows

CVE-2020-3153 is an uncontrolled search path vulnerability (CWE-427) in the Windows client of Cisco AnyConnect Secure Mobility Client, which mishandles directory paths when running with elevated privileges. An attacker or malware that already has valid credentials and local access on a Windows endpoint can copy malicious files, such as DLLs, into locations loaded by the elevated AnyConnect process. Successful exploitation yields system-level (SYSTEM) privilege execution on the endpoint via DLL preloading or DLL hijacking, making it an effective local privilege escalation step in broader intrusion chains. Any organization running the AnyConnect VPN client on Windows endpoints is potentially affected. The flaw was added to CISA KEV on 2022-10-24 with known ransomware use, and its EPSS of 28.3% (98th percentile) indicates an elevated probability of near-term exploitation, though no public PoC is known.

Do: Apply the fixed AnyConnect release per Cisco's instructions, as required by CISA's KEV listing, prioritizing Windows endpoints where the client is installed. Inventory your estate for AnyConnect installations and verify client builds are current. Given the known ransomware use, hunt for signs of local DLL planting in writable directories and review privilege-escalation activity on Windows hosts.

6.528% KEV ransomware PoC ×4
  • Cisco AnyConnect Secure Mobility Client for Windows
massmillions of enterprise Windows endpoints (AnyConnect is among the most widely deployed corporate VPN clients)
CVE-2020-3433
DLL Hijacking LPE in Cisco AnyConnect Secure Mobility Client for Windows

Cisco AnyConnect Secure Mobility Client for Windows contains a DLL hijacking flaw (CWE-427) in its interprocess communication (IPC) channel, caused by insufficient validation of resources loaded at run time. An attacker who already has valid credentials on the Windows machine can send a crafted IPC message to the AnyConnect process and coerce it into loading a malicious DLL. Successful exploitation allows arbitrary code execution with SYSTEM privileges, turning a low-privileged local foothold into full administrative control of the endpoint. Any organization running AnyConnect on Windows endpoints is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use, a public proof-of-concept is available, and news reports confirm active exploitation alongside another AnyConnect Windows flaw.

Do: Upgrade Cisco AnyConnect for Windows to a fixed release per Cisco's security advisory, as required by the CISA KEV required action (apply updates per vendor instructions). Since exploitation requires valid local credentials, limit local logon privileges on endpoints and prioritize patching given known ransomware use. Inventory Windows endpoints for AnyConnect installs and monitor for suspicious DLL loads in the AnyConnect process path.

7.810% KEV ransomware PoC
  • Cisco AnyConnect Secure Mobility Client for Windows
masstens of millions of Windows endpoints running AnyConnect (dominant enterprise VPN client installed base; no precise public count in this data)
Full article257 words · extracted from securityaffairs.com · click to collapse

Cisco warns of active exploitation attempts targeting two vulnerabilities in the Cisco AnyConnect Secure Mobility Client for Windows.

Cisco is warning of exploitation attempts targeting two security flaws, tracked as CVE-2020-3153 (CVSS score: 6.5) and CVE-2020-3433 (CVSS score: 7.8), in the Cisco AnyConnect Secure Mobility Client for Windows. Both vulnerabilities are dated 2020 and are now patched.

The CVE-2020-3153 flaw resides in the installer component of AnyConnect Secure Mobility Client for Windows, an authenticated local attacker can exploit the flaw to copy user-supplied files to system level directories with system level privileges.

The CVE-2020-3433 vulnerability resides in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows. An authenticated, local attacker can exploit the issue to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.

The alert follows the decision of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the two CISCO flaws to its Known Exploited Vulnerabilities catalog.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to address both CISCO vulnerabilities by November 14, 2022.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Cisco)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/137654/security/cisco-anyconnect-secure-mobility-flaws.html