CVE-2020-3535
published 2020-10-08CVE-2020-3535: A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a…
PriorityP344high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.59%
44.2th percentile
A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a malicious library. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. The vulnerability is due to incorrect handling of directory paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file in a specific location on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with the privileges of another user’s account.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_webex_teams | — | — |
| cisco | webex_teams | — | — |
| cisco | webex_teams | 3.0.13464.0 – 3.0.16040.0 | — |
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Webex Teams Client for Windows DLL Hijacking Vulnerability
vendor_cisco·2020-10-07·CVSS 7.8
CVE-2020-3535 [HIGH] CWE-427 Cisco Webex Teams Client for Windows DLL Hijacking Vulnerability
Cisco Webex Teams Client for Windows DLL Hijacking Vulnerability
A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a malicious library. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.
The vulnerability is due to incorrect handling of directory paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file in a specific location on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with the privileges of another user’s account.
Cisco has released software updates that address this vu
Cisco
Cisco Webex Teams Client for Windows DLL Hijacking Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-3535 Cisco Webex Teams Client for Windows DLL Hijacking Vulnerability
CVE-2020-3535: Cisco Webex Teams Client for Windows DLL Hijacking Vulnerability
A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a malicious library. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. The vulnerability is due to incorrect handling of directory paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file in a specific location on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with the privileges of another user’s account. Cisco has released software updates that ad
GHSA
GHSA-v4rq-rq59-hgx8: A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to
ghsa_unreviewed·2022-05-24
CVE-2020-3535 [HIGH] CWE-427 GHSA-v4rq-rq59-hgx8: A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to
A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a malicious library. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. The vulnerability is due to incorrect handling of directory paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file in a specific location on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with the privileges of another user’s account.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-08
Published