claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2020-3153-cisco-anyconnect-secure.log

CVE-2020-3153 — Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

2022-10-24 • CISA Known Exploited Vulnerability


[event] Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.

> AFFECTED SOFTWARE

Field Value
Vendor Cisco
Product AnyConnect Secure
CWE CWE-427
CVE ID CVE-2020-3153
Date Added 2022-10-24
Due Date 2022-11-14
Ransomware Campaign Known — this vulnerability has been leveraged in ransomware campaigns

> MITIGATION

Apply updates per vendor instructions.

Due Date: 2022-11-14

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:11 UTC