← volver
CVE-2018-0438

Cisco Umbrella Enterprise Roaming Client Privilege Escalation Vulnerability

EPSS 1.4%CWE-20
Vexday Risk Score
23Bajo
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS EPSS 1.4%KEV nãoPoC públicaNuclei Metasploit Patch referenciado
Ciclo de vida
06 sep 2018PoC pública
05 oct 2018Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vulnerability is due to improper implementation of file system permissions, which could allow non-administrative users to place files within restricted directories. An attacker could exploit this vulnerability by placing an executable file within the restricted directory, which when executed by the ERC client, would run with Administrator privileges.
Productos afectados
Cisco · Cisco Umbrella
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →