PT-2020-1762 · Cisco · Cisco Anyconnect Secure Mobility Client

Published

2020-02-19

·

Updated

2022-12-09

·

CVE-2020-3153

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco AnyConnect Secure Mobility Client for Windows versions prior to 4.8.02042
Description A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.
Recommendations For versions prior to 4.8.02042, update to version 4.8.02042 or later to resolve the issue. As a temporary workaround, consider restricting access to system level directories to minimize the risk of exploitation. Avoid using the vulnerable installer component until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Exploit

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01002
CVE-2020-3153

Affected Products

Cisco Anyconnect Secure Mobility Client