Skip to content
COOEY

EXPOSURES › CVE-2020-3153

CVE-2020-3153

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-10-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-3153 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatchedrce

Cisco AnyConnect for Windows mishandles directory paths, allowing attackers with valid credentials to copy malicious files to arbitrary locations with system-level privileges.

This unpatched vulnerability enables DLL pre-loading and hijacking, granting system-level access to attackers who already have valid credentials. DIB organizations must ensure AnyConnect is patched immediately, as this flaw was actively exploited in the wild and linked to ransomware campaigns. Failure to patch exposes the entire network to lateral movement and privilege escalation.

Shame score — A critical, actively exploited vulnerability in a widely deployed security client that was left unpatched long enough to be weaponized by ransomware actors.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized