Back

HIGH KEV Used in ransomware campaigns

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Published Aug 17, 2020 ·Due Nov 14, 2022

Description

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published Aug 17, 2020
Updated Aug 12, 2026
Reserved Dec 12, 2019
CISA Vulnrichment
Updated Nov 8, 2024
NVD
Status Analyzed
Modified Aug 12, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner cisco
Published Aug 17, 2020
Updated Aug 12, 2026
Exploited since Oct 24, 2022
EUVD-2020-24704