Aller au contenu
Toutes les vulnérabilités
CVE-2020-3433KEVRançongiciel

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Sévérité
Élevée7,8CVSS 3.1, Élevée
EPSS
10 %
Publiée
17 août 2020
Mise à jour
12 août 2026

Description

Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.

Faiblesse : CWE-427

Exploitée activement

Ajoutée au catalogue CISA KEV le 24 oct. 2022

Date limite de remédiation fédérale : 14 nov. 2022

Utilisation connue par des rançongiciels

Action requise : Apply updates per vendor instructions.

Prédiction d’exploitation

Probabilité d’exploitation de 10 % dans les 30 prochains jours (percentile 95 %).

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Produits concernés

Patcharo affiche cette vulnérabilité à titre d’information mais ne compare pas encore les versions de ce produit.

  • Cisco Cisco AnyConnect Secure Mobility Client · n/a

Références

Provenance

Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.

Cisco (CVE record)
Cisco (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
CISA Known Exploited Vulnerabilities
CISA Known Exploited Vulnerabilities · 27 sept. 2026, 23:42 UTC · Analyseur patcharo-kev/1.0.0
NVD
NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0

Dernière vérification : 28 sept. 2026, 02:31 UTC