PT-2020-4639 · Cisco · Cisco Webex Meetings Desktop App
Published
2020-11-04
·
Updated
2020-11-24
·
CVE-2020-3588
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Webex Meetings Desktop App for Windows (affected versions not specified)
Description
A vulnerability in virtualization channel messaging could allow a local attacker to execute arbitrary code on a targeted system. This issue occurs when the app is deployed in a virtual desktop environment and using virtual environment optimization, due to improper validation of messages processed by the Cisco Webex Meetings Desktop App. A local attacker with limited privileges could exploit this vulnerability by sending malicious messages to the affected software using the virtualization channel interface. A successful exploit could allow the attacker to modify the underlying operating system configuration, enabling the execution of arbitrary code with the privileges of a targeted user.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Webex Meetings Desktop App