PT-2020-4639 · Cisco · Cisco Webex Meetings Desktop App

Published

2020-11-04

·

Updated

2020-11-24

·

CVE-2020-3588

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Webex Meetings Desktop App for Windows (affected versions not specified)
Description A vulnerability in virtualization channel messaging could allow a local attacker to execute arbitrary code on a targeted system. This issue occurs when the app is deployed in a virtual desktop environment and using virtual environment optimization, due to improper validation of messages processed by the Cisco Webex Meetings Desktop App. A local attacker with limited privileges could exploit this vulnerability by sending malicious messages to the affected software using the virtualization channel interface. A successful exploit could allow the attacker to modify the underlying operating system configuration, enabling the execution of arbitrary code with the privileges of a targeted user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05191
CVE-2020-3588

Affected Products

Cisco Webex Meetings Desktop App