{"id":"CVE-2020-3153","title":"A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges","summary":"A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulne…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","cwe":["CWE-427","CWE-427"],"vendor":"cisco","product":"anyconnect_secure_mobility_client","affected":["anyconnect_secure_mobility_client < 4.8.02042"],"patched":["anyconnect_secure_mobility_client 4.8.02042"],"published":"2020-02-19","updated":"2026-08-12","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-3153","references":[{"url":"http://packetstormsecurity.com/files/157340/Cisco-AnyConnect-Secure-Mobility-Client-4.8.01090-Privilege-Escalation.html","label":"psirt@cisco.com"},{"url":"http://packetstormsecurity.com/files/158219/Cisco-AnyConnect-Path-Traversal-Privilege-Escalation.html","label":"psirt@cisco.com"},{"url":"http://packetstormsecurity.com/files/159420/Cisco-AnyConnect-Privilege-Escalation.html","label":"psirt@cisco.com"},{"url":"http://seclists.org/fulldisclosure/2020/Apr/43","label":"psirt@cisco.com"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj","label":"psirt@cisco.com"},{"url":"http://packetstormsecurity.com/files/157340/Cisco-AnyConnect-Secure-Mobility-Client-4.8.01090-Privilege-Escalation.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/158219/Cisco-AnyConnect-Path-Traversal-Privilege-Escalation.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/159420/Cisco-AnyConnect-Privilege-Escalation.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2020/Apr/43","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3153","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.28307,"epssPercentile":0.98082,"kev":true,"kevDateAdded":"2022-10-24","kevDueDate":"2022-11-14","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-12T05:52:07.471Z","exploits":{"github":3,"githubRepos":["https://github.com/shubham0d/CVE-2020-3153","https://github.com/raspberry-pie/CVE-2020-3153","https://github.com/goichot/CVE-2020-3153"],"metasploit":["exploit/windows/local/anyconnect_lpe"],"checkedAt":"2026-09-21T15:23:56.503Z"},"exploitAvailable":true,"slug":"CVE-2020-3153","body":"## Overview\n\nA vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.\n\n## Affected\n\n- `anyconnect_secure_mobility_client < 4.8.02042`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `anyconnect_secure_mobility_client 4.8.02042`","depth":"midnight","depthScore":71,"depthScoreParts":{"impact":35.8,"likelihood":5.7,"exploitation":25,"ransomware":5},"changes":[{"seq":4479,"id":"CVE-2020-3153","ts":1788887183041,"field":"exploit_available","old":"false","new":"true"},{"seq":3362,"id":"CVE-2020-3153","ts":1788886301935,"field":"exploit_available","old":"true","new":"false"},{"seq":2217,"id":"CVE-2020-3153","ts":1788882971640,"field":"exploit_available","old":"false","new":"true"},{"seq":1246,"id":"CVE-2020-3153","ts":1788882383206,"field":"exploit_available","old":"true","new":"false"},{"seq":360,"id":"CVE-2020-3153","ts":1788881817891,"field":"exploit_available","old":"false","new":"true"}]}