PT-2020-1762 · Cisco · Cisco Anyconnect Secure Mobility Client
Published
2020-02-19
·
Updated
2022-12-09
·
CVE-2020-3153
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco AnyConnect Secure Mobility Client for Windows versions prior to 4.8.02042
Description
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.
Recommendations
For versions prior to 4.8.02042, update to version 4.8.02042 or later to resolve the issue. As a temporary workaround, consider restricting access to system level directories to minimize the risk of exploitation. Avoid using the vulnerable installer component until the issue is resolved. At the moment, there is no other information about additional mitigation measures.
Exploit
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Anyconnect Secure Mobility Client