PT-2021-2166 · Cisco+1 · Webex Productivity Tools+2

Published

2021-02-17

·

Updated

2021-02-23

·

CVE-2021-1372

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Webex Meetings Desktop App and Webex Productivity Tools (affected versions not specified)
Description The issue is related to errors in processing requests in the Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows, allowing an attacker to gain unauthorized access to protected information by running a specially designed application. This vulnerability is due to the unsafe usage of shared memory by the affected software. An attacker with permissions to view system memory could exploit this vulnerability, potentially retrieving sensitive information from the shared memory, including usernames, meeting information, or authentication tokens. To exploit this vulnerability, an attacker must have valid credentials on a Microsoft Windows end-user system and must log in after another user has already authenticated with Webex on the same end-user system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01060
CVE-2021-1372

Affected Products

Cisco Webex Meetings Desktop App
Windows
Webex Productivity Tools