CVE-2020-14418: Cisco Advanced Malware Protection
High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.
A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions.
Affected products
- Cisco Advanced Malware Protection: before 7.2.13 (fixed in 7.2.13)
- Madshi Madcodehook: before 4.1.3 (fixed in 4.1.3)
- Morphisec Unified Threat Prevention Platform: before 3.5.9 (fixed in 3.5.9); from 4.0, before 4.1.2 (fixed in 4.1.2)
Published 2021-01-30. Last modified 2026-06-17.