Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.
[POC] CVE-2020-3153 — CVE-2020-3153
Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal
[POC] CVE-2020-3153 — CVE-2020-3153
POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability
[POC] CVE-2020-3153 — CVE-2020-3153
PoC for CVE-2020-3153 Cisco AnyConnect Secure Mobility Client EoP
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free