← Vulnerability feed

Vulnerability record · CVE-2020-3153 · published 19 February 2020

CVE-2020-3153: Cisco AnyConnect Windows Installer Path Handling Privilege Escalation

Cisco · Anyconnect Secure Mobility Client

The Cisco AnyConnect Secure Mobility Client for Windows installer mishandles directory paths, letting an authenticated local user copy attacker-supplied files into system-level directories with system privileges. Because the copied files land in trusted locations, the flaw enables DLL pre-loading and DLL hijacking that escalate a normal user to SYSTEM.

6.5 CVSS 3.1 Medium CISA KEV since 24 Oct 2022 Known ransomware use EPSS 28% · top 1.9% CWE-427 · Uncontrolled search path element
6.5CVSS 3.1 base score, v2 4.9
28%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 8 tagged exploit
12 Aug 2026Last modified by NVD

Description

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is in CISA KEV with known ransomware use and public exploits, though it requires authenticated local access and yields only local privilege escalation.

What it is

The Cisco AnyConnect Secure Mobility Client for Windows installer mishandles directory paths, letting an authenticated local user copy attacker-supplied files into system-level directories with system privileges. Because the copied files land in trusted locations, the flaw enables DLL pre-loading and DLL hijacking that escalate a normal user to SYSTEM.

Impact

An attacker with valid local credentials gains the ability to write arbitrary files to system directories with SYSTEM privileges, enabling privilege escalation and code execution in a high-integrity context. This can lead to full local compromise of the Windows host.

Attack surface

Reached locally on a Windows system where AnyConnect is installed; the attacker must already hold valid credentials on that host. No user interaction is required beyond the attacker's own actions, per the CVSS vector AV:L/PR:L/UI:N.

Exploitation

CVE-2020-3153 is listed in CISA KEV with a due date of 2022-11-14 and is flagged for known ransomware campaign use, and public exploit code is referenced on Packet Storm and Full Disclosure. EPSS gives a 30-day exploitation probability of roughly 28 percent (98th percentile), indicating active interest.

What to do

  • Apply the Cisco AnyConnect Secure Mobility Client update referenced in Cisco advisory cisco-sa-ac-win-path-traverse-qO4HWBsj.
  • Restrict local logon and interactive access on Windows endpoints so only trusted users can run code on hosts with AnyConnect installed.
  • Audit and harden permissions on AnyConnect installation and service directories to prevent unprivileged writes.
  • Monitor for unexpected DLLs or executables appearing in system directories and AnyConnect paths.
  • Track KEV remediation deadlines and confirm patched versions across all managed Windows endpoints.

Detection

  • Alert on new or modified DLL/EXE files written to system directories (System32, SysWOW64, Program Files) by non-system processes.
  • Monitor AnyConnect installer and service process activity for file copies into privileged paths.
  • Correlate local user activity with subsequent high-integrity process creation or service installation events.
  • Review Windows event logs for privilege escalation patterns following AnyConnect installation or repair operations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-3153 to the Known Exploited Vulnerabilities catalog on 24 October 2022 as "Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 November 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3153 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-3433Cisco AnyConnect Windows client DLL hijacking via IPC channelCisco AnyConnect Secure Mobility Client for Windows fails to properly validate resources loaded at run time, allowing a DLL hijacking attack through …KEVEPSS 10%analysed9.3CVE-2012-3088Cisco anyconnect secure mobility client vulnerabilityCisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe header…EPSS 1.8%9.3CVE-2012-2493Cisco anyconnect secure mobility client improper input validation vulnerabilityThe VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2…EPSS 3.9%9.3CVE-2011-2040Cisco anyconnect secure mobility client improper input validation vulnerabilityThe helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.5.3041, and 3.0.x before 3.0.629, on Linu…EPSS 11%7.8CVE-2023-20178Cisco anyconnect secure mobility client incorrect default permissions vulnerabilityA vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Win…EPSS 5.4%7.8CVE-2021-40124Cisco anyconnect secure mobility client improper privilege management vulnerabilityA vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local…EPSS 0.24%7.8CVE-2021-1426Cisco anyconnect secure mobility client uncontrolled search path element vulnerabilityMultiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authe…EPSS 0.25%7.8CVE-2021-1427Cisco anyconnect secure mobility client uncontrolled search path element vulnerabilityMultiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authe…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2020-3153), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.