PT-2018-2501 · Cisco · Cisco Webex Meetings Server+4

Published

2018-09-05

·

Updated

2019-10-03

·

CVE-2018-0422

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Webex Meetings client for Windows (affected versions not specified) Cisco Webex Meetings Suite (affected versions not specified) Cisco Webex Meetings (affected versions not specified) Cisco Webex Meetings Server (affected versions not specified) Cisco WebEx Network Recording Player (affected versions not specified)
Description A vulnerability in the folder permissions of Cisco Webex Meetings client could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user. The issue is due to folder permissions that grant a user the permission to read, write, and execute files in the Webex folders. An attacker could exploit this vulnerability to write malicious files to the Webex client directory, affecting all other users of the targeted device. A successful exploit could allow a user to execute commands with elevated privileges. Multiuser systems have a higher risk of exploitation because folder permissions have an impact on all users of the device.
Recommendations For Cisco Webex Meetings client for Windows, consider restricting access to the Webex client directory to minimize the risk of exploitation. For Cisco Webex Meetings Suite, temporarily disabling the execution of files from the Webex folders may help mitigate the risk until a fix is available. For Cisco Webex Meetings, restricting the ability of users to write to the Webex client directory can help reduce the risk of exploitation. For Cisco Webex Meetings Server, limiting access to the server's file system may help prevent exploitation. For Cisco WebEx Network Recording Player, avoiding the execution of unknown or untrusted files may help mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00829
CVE-2018-0422
ZDI-18-998

Affected Products

Cisco Webex Network Recording Player
Cisco Webex Meetings
Cisco Webex Meetings Server
Cisco Webex Meetings Suite
Cisco Webex Meetings Client For Windows