CVE-2025-20206 describes a DLL hijacking vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows, specifically when the Secure Firewall Posture Engine is installed. An authenticated, local attacker can exploit this by sending a crafted IPC message, leading to arbitrary code execution with SYSTEM privileges. This vulnerability is rated High severity (CVSS 7.8), requiring local access and user credentials, and has a high impact on confidentiality, integrity, and availability. Currently, there is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.1.8.105CPE matchmatch criteria | cpe:2.3:a:cisco:secure_client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.