CVE-2020-3433 is a critical DLL hijacking vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows. This flaw allows an authenticated local attacker to execute arbitrary code with SYSTEM privileges due to insufficient validation of loaded resources. With a CVSS score of 7.8 (High) and a FAUCET Risk Score of 99/100, the vulnerability presents a significant risk. It has a low attack complexity and requires local user credentials for exploitation. Notably, this CVE is actively exploited in the wild, including in known ransomware campaigns, and has publicly available Metasploit modules. The vulnerability has garnered substantial community and media attention, with multiple articles and discussions highlighting its severity and active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.9.00086CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.