SB2019090515 - Privilege escalation in Cisco Jabber Client Framework for Mac
Published: September 5, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Incorrect permissions (CVE-ID: CVE-2019-12645)
The vulnerability allows a local user to execute arbitrary code on the target device.
The vulnerability exists due to improper file level permissions on an affected device when it is running a vulnerable software. A local authenticated user can modify certain configuration files and execute arbitrary code with privileges of the installed Cisco JCF for Mac Software.
Remediation
Install update from vendor's website.