Privilege escalation in Cisco WebEx Meetings Server and Cisco Webex Meetings Suite - CVE-2018-0422

 

Privilege escalation in Cisco WebEx Meetings Server and Cisco Webex Meetings Suite - CVE-2018-0422

Published: September 5, 2018 / Updated: September 6, 2018


Vulnerability identifier: #VU14676
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0422
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists in the folder permissions due to folder permissions that grant a user the permission to read, write, and execute files in the Webex folders. A local attacker can write malicious files to the Webex client directory, affecting all other users of the targeted device and execute commands with elevated privileges.


Affected software

Cisco WebEx Meetings Server
Cisco Webex Meetings Suite

How to mitigate CVE-2018-0422

Update Cisco Webex Meetings Suite to version 32.15.20 or 33.4.
Update Cisco Webex Meeting Server to version 3.0MR2.

Cisco WebEx Meetings Server - update to 3.0MR2
Cisco Webex Meetings Suite - addressed in versions 32.15.20, 33.4

External References

Related Security Bulletins