SB2020022016 - Insecure DLL loading in Cisco AnyConnect Secure Mobility Client for Windows
Published: February 20, 2020 Updated: October 24, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insecure DLL loading (CVE-ID: CVE-2020-3153)
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the incorrect handling of directory paths in the installer component. A local user can create a malicious file, copy the file to a system directory and copy malicious files to arbitrary
locations with system level privileges. This can include DLL
pre-loading, DLL hijacking, and other related attacks.
Remediation
Install update from vendor's website.