CVE-2020-14418: Cisco Advanced Malware Protection

High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.

A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions.

Affected products

  • Cisco Advanced Malware Protection: before 7.2.13 (fixed in 7.2.13)
  • Madshi Madcodehook: before 4.1.3 (fixed in 4.1.3)
  • Morphisec Unified Threat Prevention Platform: before 3.5.9 (fixed in 3.5.9); from 4.0, before 4.1.2 (fixed in 4.1.2)

Published 2021-01-30. Last modified 2026-06-17.