Skip to content
COOEY

EXPOSURES › CVE-2020-3433

CVE-2020-3433

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-10-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-3433 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatchedrce

Cisco AnyConnect's IPC channel allowed attackers with valid Windows credentials to execute SYSTEM-level code via DLL hijacking.

The vulnerability stemmed from insufficient validation of dynamically loaded resources in the interprocess communication channel, enabling privilege escalation to SYSTEM. DIB organizations must ensure AnyConnect is patched immediately, as this flaw was actively exploited in the wild and linked to ransomware campaigns, directly impacting compliance with NIST 800-171's requirement to mitigate known vulnerabilities.

Shame score — A critical, actively exploited vulnerability in a widely deployed security client that allowed SYSTEM-level code execution, demonstrating severe negligence in patching and validation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized