QID 375576

Date Published: 2022-06-13

QID 375576: Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure Vulnerability(cisco-sa-wda-pt-msh-6LWOcZ5)

A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows
could allow an authenticated, local attacker to
gain access to sensitive information on an affected system.

Affected Products
Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools releases earlier than releases 40.6 when they are running on a Microsoft Windows end-user system.

QID Detection Logic (Authenticated):
The QID checks for vulnerable version of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools by checking the version and buildnumber respectively.

A successful exploit could allow the attacker to retrieve sensitive information from the shared memory,
including usernames, meeting information, or authentication tokens.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Customers are advised to refer to cisco-sa-wda-pt-msh-6LWOcZ5 for more information.

    CVEs related to QID 375576

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-wda-pt-msh-6LWOcZ5 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wda-pt-msh-6LWOcZ5