Cisco AnyConnect urges admins to update now to avoid security threats



Cisco is urging customers of its AnyConnect service to apply a fix for a several years-old vulnerabilities after it spotted them being abused in the wild. 

The two vulnerabilities in question are tracked as CVE-2020-3433 and CVE-2020-3153. They are found in the Cisco AnyConnect Secure Mobility Client for Windows and allow local threat actors to run DLL hijacking attacks and use system-level privileges to copy files to system directories. Should they succeed, they could run arbitrary code on target endpoints with system privileges, it was added.



Source link

Previous articleCorsair K100 Air review: Skinny keyboard, fat price
Next articleApple releases macOS Ventura, iOS 16.1 and iPadOS 16