Vulnerability record · CVE-2020-3153 · published 19 February 2020
CVE-2020-3153: Cisco AnyConnect Windows Installer Path Handling Privilege Escalation
Cisco · Anyconnect Secure Mobility Client
The Cisco AnyConnect Secure Mobility Client for Windows installer mishandles directory paths, letting an authenticated local user copy attacker-supplied files into system-level directories with system privileges. Because the copied files land in trusted locations, the flaw enables DLL pre-loading and DLL hijacking that escalate a normal user to SYSTEM.
Description
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Automated analysis
high priorityThe flaw is in CISA KEV with known ransomware use and public exploits, though it requires authenticated local access and yields only local privilege escalation.
What it is
The Cisco AnyConnect Secure Mobility Client for Windows installer mishandles directory paths, letting an authenticated local user copy attacker-supplied files into system-level directories with system privileges. Because the copied files land in trusted locations, the flaw enables DLL pre-loading and DLL hijacking that escalate a normal user to SYSTEM.
Impact
An attacker with valid local credentials gains the ability to write arbitrary files to system directories with SYSTEM privileges, enabling privilege escalation and code execution in a high-integrity context. This can lead to full local compromise of the Windows host.
Attack surface
Reached locally on a Windows system where AnyConnect is installed; the attacker must already hold valid credentials on that host. No user interaction is required beyond the attacker's own actions, per the CVSS vector AV:L/PR:L/UI:N.
Exploitation
CVE-2020-3153 is listed in CISA KEV with a due date of 2022-11-14 and is flagged for known ransomware campaign use, and public exploit code is referenced on Packet Storm and Full Disclosure. EPSS gives a 30-day exploitation probability of roughly 28 percent (98th percentile), indicating active interest.
What to do
- Apply the Cisco AnyConnect Secure Mobility Client update referenced in Cisco advisory cisco-sa-ac-win-path-traverse-qO4HWBsj.
- Restrict local logon and interactive access on Windows endpoints so only trusted users can run code on hosts with AnyConnect installed.
- Audit and harden permissions on AnyConnect installation and service directories to prevent unprivileged writes.
- Monitor for unexpected DLLs or executables appearing in system directories and AnyConnect paths.
- Track KEV remediation deadlines and confirm patched versions across all managed Windows endpoints.
Detection
- Alert on new or modified DLL/EXE files written to system directories (System32, SysWOW64, Program Files) by non-system processes.
- Monitor AnyConnect installer and service process activity for file copies into privileged paths.
- Correlate local user activity with subsequent high-integrity process creation or service installation events.
- Review Windows event logs for privilege escalation patterns following AnyConnect installation or repair operations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-3153 to the Known Exploited Vulnerabilities catalog on 24 October 2022 as "Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 November 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-3153 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3153), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.