CVE-2020-3153
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
⚠ KEVEPSS 28.3%
描述
Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.
如何修補 CVE-2020-3153
OSV 沒有提供套件對應 — 請參考下方連結尋找廠商提供的建議。
CVE-2020-3153 正在被利用嗎?
是 — CVE-2020-3153 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(0)
OSV 沒有提供套件對應。