Junglewise Threat Intelligence

CVE-2020-3433: Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

CVE-2020-3433 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-10-24

Vendors: Cisco.

Executive brief

A DLL hijacking vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows allows an authenticated local attacker to execute arbitrary code with SYSTEM privileges. The flaw exists due to insufficient validation of resources loaded at runtime, which can be triggered by sending a crafted IPC message.

Affected products

  • Cisco AnyConnect Secure Mobility Client < 4.9.00086

Timeline

  • 2020-08-17: disclosed: Initial disclosure by Cisco
  • 2022-10-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-10-24: other: NVD publication date

Related threats