CVE-2020-3153
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.
EPSS 25.09% · 96.3th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | anyconnect_secure_mobility_client | 0 |
| Cisco | Cisco AnyConnect Secure Mobility Client | unspecified |
Exploit Intelligence
- Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal (github-poc)
- Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal (github-poc)
- Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal (github-poc)
- Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal (github-poc)
- Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal (github-poc)
- Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal (github-poc)
- PoC for CVE-2020-3153 Cisco AnyConnect Secure Mobility Client EoP (github-poc)
- PoC for CVE-2020-3153 Cisco AnyConnect Secure Mobility Client EoP (github-poc)
- PoC for CVE-2020-3153 Cisco AnyConnect Secure Mobility Client EoP (github-poc)
- PoC for CVE-2020-3153 Cisco AnyConnect Secure Mobility Client EoP (github-poc)
…and 43 more exploits
Timeline
- Feb 19, 2020 CVE Published
- Apr 23, 2020 PoC Published
- Jun 10, 2020 PoC Published
- Jun 26, 2020 PoC Published
- Sep 29, 2020 PoC Published
- Oct 1, 2020 PoC Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Sep 16, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- May 1, 2022 EPSS Score
References
- 20200219 Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability vendor-advisory
- 20200421 Cisco AnyConnect elevation of privileges due to insecure handling of path names mailing-list
- http://packetstormsecurity.com/files/157340/Cisco-AnyConnect-Secure-Mobility-Client-4.8.01090-Privilege-Escalation.html url
- http://packetstormsecurity.com/files/158219/Cisco-AnyConnect-Path-Traversal-Privilege-Escalation.html url
- http://packetstormsecurity.com/files/159420/Cisco-AnyConnect-Privilege-Escalation.html url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3153 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-3153 advisory