CVE-2020-3153 is a local privilege escalation vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows. It allows an authenticated local attacker to copy arbitrary files to system directories with system-level privileges, potentially leading to DLL hijacking and other attacks. The vulnerability has a CVSS score of 6.5 (Medium) and requires valid user credentials for exploitation. This flaw is actively exploited in the wild, including in known ransomware campaigns, and has a Metasploit module available. Its EPSS score is 0.25087, indicating a higher likelihood of exploitation compared to most CVEs. The vulnerability has garnered significant community discussion and media coverage, with multiple articles detailing its exploitation and Cisco's warnings.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.8.02042CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.