#VU34081 Insecure DLL loading in Cisco AnyConnect Secure Mobility Client - CVE-2020-3433
Published: August 6, 2020 / Updated: October 24, 2022
Cisco AnyConnect Secure Mobility Client
Cisco Systems, Inc
Description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner in the interprocess communication (IPC) channel. A local user can send a specially crafted IPC message to the AnyConnect process and execute arbitrary code on victim's system.