CVE detail
CVE-2020-3153
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- 31st October – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 31st October, please download our Threat Intelligence Bulletin. Top Attacks and Breaches US-based communications company Twilio has disclosed a new data breach that occurred on June 2022 allegedly by the same threat actors behind the August hack. The hackers have used voice phishing to trick a Twilio […]
vendorresearch.checkpoint.comOct 31, 2022, 9:33 AM Cisco has confirmed that two vulnerabilities affecting one of its VPN products are being exploited in the wild.
newswww.securityweek.comOct 26, 2022, 10:39 AMCisco warns of active exploitation attempts targeting two vulnerabilities in the Cisco AnyConnect Secure Mobility Client for Windows. Cisco is warning of exploitation attempts targeting two security flaws, tracked as CVE-2020-3153 (CVSS score: 6.5) and CVE-2020-3433 (CVSS score: 7.8), in the Cisco AnyConnect Secure Mobility Client for Windows. Both vulnerabilities are dated 2020 and are now patched. The […]
newssecurityaffairs.comOct 26, 2022, 9:37 AMThe US Cybersecurity and Infrastructure Security Agency (CISA) has added two Cisco and four Gigabyte product flaws to its Known Exploited Vulnerabilities catalog. Only one of the Gigabyte vulnerabilities was previously mentioned as being involved in attacks.
newswww.securityweek.comOct 25, 2022, 11:22 AMNo excerpt available.
Mitigationwww.cisa.govFeb 19, 2020, 8:15 PM- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsjtools.cisco.com
No excerpt available.
Vendor Advisorytools.cisco.comFeb 19, 2020, 8:15 PM - http://seclists.org/fulldisclosure/2020/Apr/43seclists.org
No excerpt available.
Exploitseclists.orgFeb 19, 2020, 8:15 PM - http://packetstormsecurity.com/files/159420/Cisco-AnyConnect-Privilege-Escalation.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comFeb 19, 2020, 8:15 PM - http://packetstormsecurity.com/files/158219/Cisco-AnyConnect-Path-Traversal-Privilege-Escalation.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comFeb 19, 2020, 8:15 PM - http://packetstormsecurity.com/files/157340/Cisco-AnyConnect-Secure-Mobility-Client-4.8.01090-Privilege-Escalation.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comFeb 19, 2020, 8:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-1567CVSS 7.0 · High
A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack…
- CVE-2021-1496CVSS 7.0 · High
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hi…
- CVE-2021-1430CVSS 7.0 · High
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hi…
- CVE-2021-1429CVSS 7.0 · High
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hi…
- CVE-2021-1428CVSS 7.0 · High
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hi…
- CVE-2021-1427CVSS 7.0 · High
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hi…