Remote code execution in AirWatch Agent - CVE-2018-6968
Published: June 12, 2018
Vulnerability identifier: #VU13260
CSH Severity: High
CVSS v4: 6.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2018-6968
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated administrative attacker to execute arbitrary code on the target system.
The weakness exists due to a flaw in the real time File Manager function. A remote attacker can create files in the Agent sandbox and other publicly accessible directories (e.g., SD card) and execute execute arbitrary code with elevated privileges.
Affected software
AirWatch Agent
How to mitigate CVE-2018-6968
Update to version 6.2, 8.5.2.
AirWatch Agent - addressed in versions 6.5.2, 8.2