Directory Path Mismanagement in Cisco AnyConnect Secure Mobility Client for Mac OS
CVE-2020-3432
What is CVE-2020-3432?
A vulnerability exists in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS, allowing an authenticated local attacker to exploit the improper handling of directory paths. By creating a symbolic link to a targeted file, the attacker can potentially corrupt the contents of the file. The impact of this vulnerability can include the modification of critical system files, possibly leading to denial of service for applications relying on those files. Exploiting this vulnerability requires valid user credentials on the affected system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Secure Client
References
CVSS V3.1
CVSS V3.0
Timeline
- ๐พ
Exploit known to exist
Vulnerability published