← Back to CVE List
Vulnerability Intelligence Report
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

CVE-2020-3153

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
6.5
MEDIUM
Exploitability:2.1
Impact Score:4.0
EPSS Probability:27.45%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

Affected Products & Versions

Vendor Product Affected Versions
Cisco Cisco AnyConnect Secure Mobility Client unspecified < n/a (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
27.451%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCisco Systems, Inc. · Hosted Service · USA
Reserved2019-12-12T00:00:00
Published2020-02-19T19:15:53
Patch Date2020-02-19
Last Updated2026-08-12T03:55:40

LINK COPIED TO CLIPBOARD