Cisco Webex Productivity Tools vulnerabilities

3 known vulnerabilities affecting cisco/webex_productivity_tools.

Total CVEs
3
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH3

Vulnerabilities

Page 1 of 1
CVE-2019-1674HIGHCVSS 8.8PoC≥ 32.6.0, < 33.0.72019-02-28
CVE-2019-1674 [HIGH] CWE-78 CVE-2019-1674: A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivi A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by invoking
nvd
CVE-2018-15442HIGHCVSS 7.8PoC≥ 32.6.0, < 33.0.62018-10-24
CVE-2018-15442 [HIGH] CWE-78 CVE-2018-15442: A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by invoking the update service command with a
nvd
CVE-2016-4349HIGHCVSS 7.8v2.40.5001.100122016-04-28
CVE-2016-4349 [HIGH] CVE-2016-4349: Untrusted search path vulnerability in Cisco WebEx Productivity Tools 2.40.5001.10012 allows local u Untrusted search path vulnerability in Cisco WebEx Productivity Tools 2.40.5001.10012 allows local users to gain privileges via a Trojan horse cryptsp.dll, dwmapi.dll, msimg32.dll, ntmarta.dll, propsys.dll, riched20.dll, rpcrtremote.dll, secur32.dll, sxs.dll, or uxtheme.dll file in the current working directory, aka Bug ID CSCuy56140.
nvd