CVE-2018-0422
published 2018-10-05CVE-2018-0422: A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored…
PriorityP336high7.3CVSS 3.0
AVLACLPRLUIRSUCHIHAH
EPSS
1.07%
61.0th percentile
A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user. The vulnerability is due to folder permissions that grant a user the permission to read, write, and execute files in the Webex folders. An attacker could exploit this vulnerability to write malicious files to the Webex client directory, affecting all other users of the targeted device. A successful exploit could allow a user to execute commands with elevated privileges. Attacks on single-user systems are less likely to occur, as the attack must be carried out by the user on the user's own system. Multiuser systems have a higher risk of exploitation because folder permissions have an impact on all users of the device. For an attacker to exploit this vulnerability successfully, a second user must execute the locally installed malicious file to allow remote code execution to occur.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_business_suite_32 | < 32.15.20 | 32.15.20 |
| cisco | webex_business_suite_33 | < 33.4 | 33.4 |
| cisco | webex_meetings | — | — |
| cisco | webex_meetings_online | < 1.3.37 | 1.3.37 |
| cisco | webex_meetings_online | — | — |
| cisco | webex_meetings_online | — | — |
| cisco | webex_meetings_server | <= 3.0 | — |
| cisco | webex_meetings_server | — | — |
CVSS provenance
nvdv3.07.3HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9mx2-579m-fvfq: A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally st
ghsa_unreviewed·2022-05-13
CVE-2018-0422 [HIGH] CWE-732 GHSA-9mx2-579m-fvfq: A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally st
A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user. The vulnerability is due to folder permissions that grant a user the permission to read, write, and execute files in the Webex folders. An attacker could exploit this vulnerability to write malicious files to the Webex client directory, affecting all other users of the targeted device. A successful exploit could allow a user to execute commands with elevated privileges. Attacks on single-user systems are less likely to occur, as the attack must be carried out by the user on the user's own system. Multiuser systems have a higher risk of exploitation because
Cisco
Cisco Webex Meetings Client for Windows Privilege Escalation Vulnerability
vendor_cisco·2018-09-05·CVSS 7.3
CVE-2018-0422 [HIGH] CWE-264 Cisco Webex Meetings Client for Windows Privilege Escalation Vulnerability
Cisco Webex Meetings Client for Windows Privilege Escalation Vulnerability
A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user.
The vulnerability is due to folder permissions that grant a user the permission to read, write, and execute files in the Webex folders. An attacker could exploit this vulnerability to write malicious files to the Webex client directory, affecting all other users of the targeted device. A successful exploit could allow a user to execute commands with elevated privileges.
Attacks on single-user systems are less likely to occur, as the attack must be carried out by the user on the us
Cisco
Cisco Webex Meetings Client for Windows Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0422 Cisco Webex Meetings Client for Windows Privilege Escalation Vulnerability
CVE-2018-0422: Cisco Webex Meetings Client for Windows Privilege Escalation Vulnerability
A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user. The vulnerability is due to folder permissions that grant a user the permission to read, write, and execute files in the Webex folders. An attacker could exploit this vulnerability to write malicious files to the Webex client directory, affecting all other users of the targeted device. A successful exploit could allow a user to execute commands with elevated privileges. Attacks on single-user systems are less likely to occur, as the attack must be carried out by the us
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/105281http://www.securitytracker.com/id/1041681https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-webex-pehttp://www.securityfocus.com/bid/105281http://www.securitytracker.com/id/1041681https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-webex-pe
2018-10-05
Published