← Vulnerability feed

Vulnerability record · CVE-2020-3433 · published 17 August 2020

CVE-2020-3433: Cisco AnyConnect Windows client DLL hijacking via IPC channel

Cisco · Anyconnect Secure Mobility Client

Cisco AnyConnect Secure Mobility Client for Windows fails to properly validate resources loaded at run time, allowing a DLL hijacking attack through a crafted IPC message to the AnyConnect process. An attacker who already holds valid Windows credentials can exploit this locally to escalate to SYSTEM. It matters because the flaw is confirmed exploited in the wild and has been used in ransomware campaigns.

7.8 CVSS 3.1 High CISA KEV since 24 Oct 2022 Known ransomware use EPSS 10% · top 4.5% CWE-427 · Uncontrolled search path element
7.8CVSS 3.1 base score, v2 7.2
10%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
12 Aug 2026Last modified by NVD

Description

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityConfirmed exploitation in the wild and ransomware association raise urgency, though the attack requires local authenticated access and a CVSS base of 7.8 rather than a remotely reachable flaw.

What it is

Cisco AnyConnect Secure Mobility Client for Windows fails to properly validate resources loaded at run time, allowing a DLL hijacking attack through a crafted IPC message to the AnyConnect process. An attacker who already holds valid Windows credentials can exploit this locally to escalate to SYSTEM. It matters because the flaw is confirmed exploited in the wild and has been used in ransomware campaigns.

Impact

An attacker gains arbitrary code execution with SYSTEM privileges on the affected Windows machine, effectively full control of the host. This enables credential theft, persistence, and lateral movement from a low-privileged starting point.

Attack surface

Reached locally by sending a crafted IPC message to the AnyConnect process; the vector is AV:L, so no network exposure and no user interaction (UI:N) is required. Authentication is required: the attacker must already have valid credentials on the Windows system (PR:L).

Exploitation

Listed in CISA KEV with a due date of 2022-11-14 and flagged for known ransomware campaign use, and a public exploit reference exists (Packet Storm). EPSS 30-day probability is about 10 percent (95th percentile), indicating elevated likelihood.

What to do

  • Apply the Cisco AnyConnect updates referenced in the vendor advisory cisco-sa-anyconnect-dll-F26WwJW as the first action.
  • Restrict and monitor local logon rights so unprivileged users cannot run code on endpoints where AnyConnect is installed.
  • Enforce least privilege and remove unnecessary local accounts to reduce the pool of credentials usable for this local attack.
  • Where feasible, constrain write access to directories searched during DLL loading to prevent planting of malicious libraries.

Detection

  • Monitor for unexpected DLL loads by the AnyConnect process, especially libraries loaded from user-writable paths.
  • Alert on anomalous IPC activity directed at the AnyConnect process from non-standard or low-privileged processes.
  • Hunt for new or modified DLL files in directories adjacent to AnyConnect binaries and in user-writable search paths.
  • Correlate AnyConnect process activity with subsequent SYSTEM-level child process creation on the same host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-3433 to the Known Exploited Vulnerabilities catalog on 24 October 2022 as "Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 November 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3433 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.5CVE-2020-3153Cisco AnyConnect Windows Installer Path Handling Privilege EscalationThe Cisco AnyConnect Secure Mobility Client for Windows installer mishandles directory paths, letting an authenticated local user copy attacker-suppl…KEVEPSS 28%analysed9.3CVE-2012-3088Cisco anyconnect secure mobility client vulnerabilityCisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe header…EPSS 1.8%9.3CVE-2012-2493Cisco anyconnect secure mobility client improper input validation vulnerabilityThe VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2…EPSS 3.9%9.3CVE-2011-2040Cisco anyconnect secure mobility client improper input validation vulnerabilityThe helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.5.3041, and 3.0.x before 3.0.629, on Linu…EPSS 11%7.8CVE-2023-20178Cisco anyconnect secure mobility client incorrect default permissions vulnerabilityA vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Win…EPSS 5.4%7.8CVE-2021-40124Cisco anyconnect secure mobility client improper privilege management vulnerabilityA vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local…EPSS 0.24%7.8CVE-2021-1426Cisco anyconnect secure mobility client uncontrolled search path element vulnerabilityMultiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authe…EPSS 0.25%7.8CVE-2021-1427Cisco anyconnect secure mobility client uncontrolled search path element vulnerabilityMultiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authe…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2020-3433), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.