CVE-2020-3433
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
⚠ KEVEPSS 10.0%
描述
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.
如何修補 CVE-2020-3433
OSV 沒有提供套件對應 — 請參考下方連結尋找廠商提供的建議。
CVE-2020-3433 正在被利用嗎?
是 — CVE-2020-3433 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(0)
OSV 沒有提供套件對應。