← Back to browse · API

CVE-2020-3153

Severity
MEDIUM
CVSS
6.5
EPSS
0.27451
Risk score
60.61
CISA KEV
Yes
PoC
No
Published
2020-02-19
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2020-24424, GHSA-XPXV-RFWH-RCFC
Products
Cisco:AnyConnect Secure, Cisco:Cisco AnyConnect Secure Mobility Client unspecified <n/a
Sources
cisa.gov CVE-2020-3153
euvd EUVD-2020-24424

Description

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.

References