Cisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
61Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 7.8epss 16%
da publicação à arma1 dias
Publicada no NVD24 de out.
1ª PoC+1d
metasploit9 de out.
probabilidade de exploração
16%top 3% das CVEs
exploração observada
nãonenhuma fonte reporta
4 exploit(s) público(s)
A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by invoking the update service command with a crafted argument. An exploit could allow the attacker to run arbitrary commands with SYSTEM user privileges. While the CVSS Attack Vector metric denotes the requirement for an attacker to have local access, administrators should be aware that in Active Directory deployments, the vulnerability could be exploited remotely by leveraging the operating system remote management tools.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Cisco · Cisco WebEx Event CenterPoCs públicas encontradas — 4✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45696exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45695cve_referencewww.exploit-db.com/exploits/45695/não verificadocve_referencewww.exploit-db.com/exploits/45696/não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.