ID:4663 - Exploit for Insecure DLL loading in Cisco AnyConnect Secure Mobility Client - CVE-2020-3433
Published: September 28, 2020
Cisco AnyConnect Secure Mobility Client
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner in the interprocess communication (IPC) channel. A local user can send a specially crafted IPC message to the AnyConnect process and execute arbitrary code on victim's system.