CVE ID | CVE-2018-0422 |
CVSS SCORE | 6.9, AV:L/AC:M/Au:N/C:C/I:C/A:C |
AFFECTED VENDORS |
Cisco |
AFFECTED PRODUCTS |
WebEx |
VULNERABILITY DETAILS |
The specific flaw exists in the access control that the product installer sets on the product's binaries. This allows any local user to replace the product's binaries with malicious replacements. An attacker can leverage this vulnerability to escalate privileges to the level of some other user of the system, such as an administrator. |
ADDITIONAL DETAILS |
Cisco has issued an update to correct this vulnerability. More details can be found at:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-webex-pe
This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 120 day deadline. 02/07/18 - ZDI reported vulnerability to Vendor -- Mitigation: |
DISCLOSURE TIMELINE |
|
CREDIT | Simon Zuckerbraun of Trend Micro Zero Day Initiative |