Cisco Webex Meetings Desktop App CVE-2018-15442 Local Command Injection Vulnerability
BID:105734
CVE-2018-15442 |Info
Cisco Webex Meetings Desktop App CVE-2018-15442 Local Command Injection Vulnerability
| Bugtraq ID: | 105734 |
| Class: | Unknown |
| CVE: |
CVE-2018-15442 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 24 2018 12:00AM |
| Updated: | Oct 24 2018 12:00AM |
| Credit: | Ron Bowes and Jeff McJunkin of Counter Hack. |
| Vulnerable: |
Cisco WebEx Productivity Tools 32.6 Cisco WebEx Productivity Tools 2.40.5001.10012 Cisco WebEx Productivity Tools 2.32.600.15324 Cisco WebEx Productivity Tools 2.32 Cisco WebEx Productivity Tools 2.23 Cisco WebEx Productivity Tools 2.20.2200 Cisco Webex Meetings Desktop App 0 |
| Not Vulnerable: |
Cisco WebEx Productivity Tools 33.0.5 Cisco Webex Meetings Desktop App 33.6 |
Discussion
Cisco Webex Meetings Desktop App CVE-2018-15442 Local Command Injection Vulnerability
Cisco Webex Meetings Desktop App is prone to a local command-injection vulnerability.
An attacker may exploit this issue to inject and execute arbitrary commands with SYSTEM user privileges; this may aid in further attacks.
This issue being tracked by Cisco Bug ID CSCvk70841.
Cisco Webex Meetings Desktop App is prone to a local command-injection vulnerability.
An attacker may exploit this issue to inject and execute arbitrary commands with SYSTEM user privileges; this may aid in further attacks.
This issue being tracked by Cisco Bug ID CSCvk70841.
Exploit / POC
Cisco Webex Meetings Desktop App CVE-2018-15442 Local Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco Webex Meetings Desktop App CVE-2018-15442 Local Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Webex Meetings Desktop App CVE-2018-15442 Local Command Injection Vulnerability
References:
References: