Remote code execution in AirWatch Agent - CVE-2018-6968

 

Remote code execution in AirWatch Agent - CVE-2018-6968

Published: June 12, 2018


Vulnerability identifier: #VU13260
CSH Severity: High
CVSS v4: 6.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2018-6968
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated administrative attacker to execute arbitrary code on the target system.
The weakness exists due to a flaw in the real time File Manager function. A remote attacker can create files in the Agent sandbox and other publicly accessible directories (e.g., SD card) and execute execute arbitrary code with elevated privileges.


Affected software

AirWatch Agent

How to mitigate CVE-2018-6968

Update to version 6.2, 8.5.2.

AirWatch Agent - addressed in versions 6.5.2, 8.2

External References

Related Security Bulletins