Vulnerability record · CVE-2020-3433 · published 17 August 2020
CVE-2020-3433: Cisco AnyConnect Windows client DLL hijacking via IPC channel
Cisco · Anyconnect Secure Mobility Client
Cisco AnyConnect Secure Mobility Client for Windows fails to properly validate resources loaded at run time, allowing a DLL hijacking attack through a crafted IPC message to the AnyConnect process. An attacker who already holds valid Windows credentials can exploit this locally to escalate to SYSTEM. It matters because the flaw is confirmed exploited in the wild and has been used in ransomware campaigns.
Description
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityConfirmed exploitation in the wild and ransomware association raise urgency, though the attack requires local authenticated access and a CVSS base of 7.8 rather than a remotely reachable flaw.
What it is
Cisco AnyConnect Secure Mobility Client for Windows fails to properly validate resources loaded at run time, allowing a DLL hijacking attack through a crafted IPC message to the AnyConnect process. An attacker who already holds valid Windows credentials can exploit this locally to escalate to SYSTEM. It matters because the flaw is confirmed exploited in the wild and has been used in ransomware campaigns.
Impact
An attacker gains arbitrary code execution with SYSTEM privileges on the affected Windows machine, effectively full control of the host. This enables credential theft, persistence, and lateral movement from a low-privileged starting point.
Attack surface
Reached locally by sending a crafted IPC message to the AnyConnect process; the vector is AV:L, so no network exposure and no user interaction (UI:N) is required. Authentication is required: the attacker must already have valid credentials on the Windows system (PR:L).
Exploitation
Listed in CISA KEV with a due date of 2022-11-14 and flagged for known ransomware campaign use, and a public exploit reference exists (Packet Storm). EPSS 30-day probability is about 10 percent (95th percentile), indicating elevated likelihood.
What to do
- Apply the Cisco AnyConnect updates referenced in the vendor advisory cisco-sa-anyconnect-dll-F26WwJW as the first action.
- Restrict and monitor local logon rights so unprivileged users cannot run code on endpoints where AnyConnect is installed.
- Enforce least privilege and remove unnecessary local accounts to reduce the pool of credentials usable for this local attack.
- Where feasible, constrain write access to directories searched during DLL loading to prevent planting of malicious libraries.
Detection
- Monitor for unexpected DLL loads by the AnyConnect process, especially libraries loaded from user-writable paths.
- Alert on anomalous IPC activity directed at the AnyConnect process from non-standard or low-privileged processes.
- Hunt for new or modified DLL files in directories adjacent to AnyConnect binaries and in user-writable search paths.
- Correlate AnyConnect process activity with subsequent SYSTEM-level child process creation on the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-3433 to the Known Exploited Vulnerabilities catalog on 24 October 2022 as "Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 November 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/159420/Cisco-AnyConnect-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW | Vendor Advisory |
| http://packetstormsecurity.com/files/159420/Cisco-AnyConnect-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3433 | US Government Resource |
Track CVE-2020-3433 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3433), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.