Insecure DLL loading in Cisco AnyConnect Secure Mobility Client - CVE-2020-3153
Published: February 20, 2020 / Updated: October 24, 2022
Vulnerability details
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the incorrect handling of directory paths in the installer component. A local user can create a malicious file, copy the file to a system directory and copy malicious files to arbitrary
locations with system level privileges. This can include DLL
pre-loading, DLL hijacking, and other related attacks.
Affected software
How to mitigate CVE-2020-3153
Links to Public Exploits and PoC-codes
- Exploit #4667 - Cisco AnyConnect Privilege Escalations (CVE-2020-3153 and CVE-2020-3433) (September 30, 2020)
- Exploit #3052 - Cisco AnyConnect Priv Esc through Path Traversal (July 2, 2020)
- Exploit #2974 - CVE-2020-3153 (PoC for CVE-2020-3153 Cisco AnyConnect Secure Mobility Client EoP) (June 3, 2020)
- Exploit #2997 - CVE-2020-3153 (Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal) (June 3, 2020)
- Exploit #2662 - CVE-2020-3153 (POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability) (May 13, 2020)