EXPOSURES › CVE-2020-3433
CVE-2020-3433
CRITICAL ⌖ ON CISA KEV · EXPLOITEDCisco AnyConnect's IPC channel allowed attackers with valid Windows credentials to execute SYSTEM-level code via DLL hijacking.
The vulnerability stemmed from insufficient validation of dynamically loaded resources in the interprocess communication channel, enabling privilege escalation to SYSTEM. DIB organizations must ensure AnyConnect is patched immediately, as this flaw was actively exploited in the wild and linked to ransomware campaigns, directly impacting compliance with NIST 800-171's requirement to mitigate known vulnerabilities.
Shame score — A critical, actively exploited vulnerability in a widely deployed security client that allowed SYSTEM-level code execution, demonstrating severe negligence in patching and validation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |