---
id: CVE-2020-3153
title: >-
  A vulnerability in the installer component of Cisco AnyConnect Secure Mobility
  Client for Windows could allow an authenticated local attacker to copy
  user-supplied files to system level directories with system level privileges
summary: >-
  A vulnerability in the installer component of Cisco AnyConnect Secure Mobility
  Client for Windows could allow an authenticated local attacker to copy
  user-supplied files to system level directories with system level privileges.
  The vulne…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'
cwe:
  - CWE-427
  - CWE-427
vendor: cisco
product: anyconnect_secure_mobility_client
affected:
  - anyconnect_secure_mobility_client < 4.8.02042
patched:
  - anyconnect_secure_mobility_client 4.8.02042
published: '2020-02-19'
updated: '2026-08-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-3153'
references:
  - url: >-
      http://packetstormsecurity.com/files/157340/Cisco-AnyConnect-Secure-Mobility-Client-4.8.01090-Privilege-Escalation.html
    label: psirt@cisco.com
  - url: >-
      http://packetstormsecurity.com/files/158219/Cisco-AnyConnect-Path-Traversal-Privilege-Escalation.html
    label: psirt@cisco.com
  - url: >-
      http://packetstormsecurity.com/files/159420/Cisco-AnyConnect-Privilege-Escalation.html
    label: psirt@cisco.com
  - url: 'http://seclists.org/fulldisclosure/2020/Apr/43'
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj
    label: psirt@cisco.com
  - url: >-
      http://packetstormsecurity.com/files/157340/Cisco-AnyConnect-Secure-Mobility-Client-4.8.01090-Privilege-Escalation.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/158219/Cisco-AnyConnect-Path-Traversal-Privilege-Escalation.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/159420/Cisco-AnyConnect-Privilege-Escalation.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2020/Apr/43'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3153
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.28307
epssPercentile: 0.98035
kev: true
kevDateAdded: '2022-10-24'
kevDueDate: '2022-11-14'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-12T05:52:07.471Z'
exploits:
  github: 3
  githubRepos:
    - 'https://github.com/shubham0d/CVE-2020-3153'
    - 'https://github.com/raspberry-pie/CVE-2020-3153'
    - 'https://github.com/goichot/CVE-2020-3153'
  metasploit:
    - exploit/windows/local/anyconnect_lpe
  checkedAt: '2026-09-24T07:52:47.138Z'
exploitAvailable: true
---

## Overview

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.

## Affected

- `anyconnect_secure_mobility_client < 4.8.02042`

## Remediation

Upgrade past the affected range:

- `anyconnect_secure_mobility_client 4.8.02042`
