Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2021-1280
Cisco Secure Endpoint vulnerability analysis and mitigation

Overview

A vulnerability in the loading mechanism of specific DLLs of Cisco Advanced Malware Protection (AMP) for Endpoints for Windows and Immunet for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. The vulnerability, identified as CVE-2021-1280, requires valid credentials on the Windows system for exploitation. This vulnerability was discovered and disclosed in January 2021, affecting all Cisco AMP for Endpoints for Windows releases earlier than Release 7.3.3 and all Immunet for Windows releases earlier than Release 7.3.12 (Cisco Advisory).

Technical details

The vulnerability is due to incorrect handling of directory search paths at runtime. The issue has been assigned a CVSS base score of 7.8 (High) with the vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The vulnerability is classified under CWE-427 (Cisco Advisory).

Impact

A successful exploit could allow the attacker to execute arbitrary code on the targeted system with SYSTEM privileges. The vulnerability affects Windows-based systems running vulnerable versions of Cisco AMP for Endpoints or Immunet (Cisco Advisory).

Exploitability

An attacker could exploit this vulnerability by placing a malicious DLL file on the targeted system. The file will execute when the vulnerable application launches. The exploitation requires local access and valid credentials on the Windows system. As of the advisory's publication, Cisco PSIRT was not aware of any malicious use of this vulnerability (Cisco Advisory).

Mitigation and workarounds

Cisco has released software updates that address this vulnerability in Cisco AMP for Endpoints for Windows releases 7.3.3 and later, and Immunet for Windows releases 7.3.12 and later. There are no workarounds available for this vulnerability (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Secure Endpoint vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-1386HIGH7.8
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesApr 08, 2021
CVE-2021-1280HIGH7.3
  • Cisco Secure Endpoint logoCisco Secure Endpoint
  • cpe:2.3:a:cisco:advanced_malware_protection_for_endpoints
NoYesJan 20, 2021
CVE-2020-3350MEDIUM6.3
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesJun 18, 2020
CVE-2020-3344MEDIUM5.5
  • Cisco Secure Endpoint logoCisco Secure Endpoint
  • cpe:2.3:a:cisco:advanced_malware_protection_for_endpoints
NoYesMay 22, 2020
CVE-2020-3343MEDIUM5.5
  • Cisco Secure Endpoint logoCisco Secure Endpoint
  • cpe:2.3:a:cisco:advanced_malware_protection_for_endpoints
NoYesMay 22, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management