← Vulnerability feed

Vulnerability record · CVE-2025-20206 · published 5 March 2025

CVE-2025-20206: Cisco secure client improper verification of cryptographic signature vulnerability

Cisco · Secure Client

A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the Secure Firewall Posture Engine, formerly HostScan, is installed on Cisco Secure Client. This vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to a specific Cisco Secure Client process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker must have valid user credentials on the Windows system.

7.8 CVSS 3.1 High EPSS 0.18% · top 93.6% CWE-347 · Improper verification of cryptographic signature
7.8CVSS 3.1 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the Secure Firewall Posture Engine, formerly HostScan, is installed on Cisco Secure Client. This vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to a specific Cisco Secure Client process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker must have valid user credentials on the Windows system.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-20206 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2024-20337Cisco secure client vulnerabilityA vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage retur…EPSS 30%7.8CVE-2023-20178Cisco anyconnect secure mobility client incorrect default permissions vulnerabilityA vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Win…EPSS 5.4%7.6CVE-2024-3661Fortinet forticlient missing authentication for critical function vulnerabilityDHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redi…EPSS 4.1%7.3CVE-2024-20338Cisco secure client uncontrolled search path element vulnerabilityA vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate priv…EPSS 0.89%6.8CVE-2024-20391Cisco secure client missing authentication for critical function vulnerabilityA vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an …EPSS 0.35%6.5CVE-2024-20474Cisco anyconnect secure mobility client vulnerabilityA vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker…EPSS 0.60%5.5CVE-2023-20240Cisco anyconnect secure mobility client out-of-bounds read vulnerabilityMultiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to…EPSS 0.20%5.5CVE-2023-20241Cisco anyconnect secure mobility client out-of-bounds read vulnerabilityMultiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to…EPSS 0.20%

Source: NIST National Vulnerability Database (record CVE-2025-20206), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.