CVE-2020-3433
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 7.8
- EPSS
- 10.1% 백분위 95.1% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.11.14
- 공개일
- 2020.08.18
CISA KEV에 등록된 실제 악용 확인 취약점
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on t...
공급사 Cisco
제품 AnyConnect Secure
영향 버전 n/a, < 4.9.00086
수정 버전 4.9.00086
Apply updates per vendor instructions.
조치 기한: 2022.11.14CVSS 벡터 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE CWE-427
KEV 등록일 2022.10.24
랜섬웨어 캠페인 사용 확인됨
CISA 비고 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW; https://nvd.nist.gov/vuln/detail/CVE-2020-3433
EPSS 데이터 기준일 2026.06.27