Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
- Sévérité
- Élevée7,8CVSS 3.1, Élevée
- EPSS
- 10 %
- Publiée
- 17 août 2020
- Mise à jour
- 12 août 2026
Description
Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.
Faiblesse : CWE-427
Exploitée activement
Ajoutée au catalogue CISA KEV le 24 oct. 2022
Date limite de remédiation fédérale : 14 nov. 2022
Utilisation connue par des rançongiciels
Action requise : Apply updates per vendor instructions.
Prédiction d’exploitation
Probabilité d’exploitation de 10 % dans les 30 prochains jours (percentile 95 %).
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produits concernés
Patcharo affiche cette vulnérabilité à titre d’information mais ne compare pas encore les versions de ce produit.
- Cisco Cisco AnyConnect Secure Mobility Client · n/a
Références
Provenance
Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.
- Cisco (CVE record)
- Cisco (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 sept. 2026, 23:42 UTC · Analyseur patcharo-kev/1.0.0
- NVD
- NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0
Dernière vérification : 28 sept. 2026, 02:31 UTC