Skip to main content

CVE-2020-3433

7.8
HIGHCVSS v3.1 Base Score
4.46%
LOW RiskEPSS (89th percentile)
KEV

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.

Published: 8/17/2020
Modified: 10/28/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Vendor / Product:

Cisco AnyConnect Secure

Required Action:

Apply updates per vendor instructions.

Due Date: 11/14/2022(OVERDUE)
Ransomware Campaign Use
Added to KEV:

10/24/2022

Notes:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW; https://nvd.nist.gov/vuln/detail/CVE-2020-3433

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

4.46%LOW Exploitation Risk
89th percentile

This vulnerability has a 4.46% probability of being exploited in the next 30 days, ranking higher than 89% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-427)

Similar SeverityHIGH