THREAT OPS › Threat News › [NVD] CVE-2020-3433 (HIGH 7.8) — A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials
[NVD] CVE-2020-3433 (HIGH 7.8) — A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials
CVE-2020-3433 CVSS: 7.8 HIGH Published: 2020-08-17T18:15:12.947
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insu
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2020-3433cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2020-3433