← KEV catalog
CISA known exploited vulnerability

CVE-2020-3433

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

SOURCE FACT

Cisco · AnyConnect Secure

Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.

Required action

Apply updates per vendor instructions.

CISA notes

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW; https://nvd.nist.gov/vuln/detail/CVE-2020-3433

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?