CVE-2020-3153
KEV RANSOMWAREMEDIUM 6.5EPSS 28.3%
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N - CVSS v3.0
- 6.5 MEDIUM
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N - CVSS v2.0
- 4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:C/A:N - EPSS
- 28.31% chance of exploitation in the next 30 days, 98th percentile
- CISA KEV
- added 2022-10-24, used in ransomware campaigns
- Published
- 2020-02-19
- Updated
- 2026-08-12
Proof-of-concept exploits (6)
- http://packetstormsecurity.com/files/157340/Cisco-AnyConnect-Secure-Mobility-Client-4.8.0…
- http://packetstormsecurity.com/files/158219/Cisco-AnyConnect-Path-Traversal-Privilege-Esc…
- http://packetstormsecurity.com/files/159420/Cisco-AnyConnect-Privilege-Escalation.html
- goichot/CVE-2020-3153103★ · 2020-05-25
- raspberry-pie/CVE-2020-31530★ · 2020-05-15
- shubham0d/CVE-2020-31535★ · 2020-05-04