// For flags

CVE-2019-1674

Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools Update Service Command Injection Vulnerability

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by invoking the update service command with a crafted argument. An exploit could allow the attacker to run arbitrary commands with SYSTEM user privileges. While the CVSS Attack Vector metric denotes the requirement for an attacker to have local access, administrators should be aware that in Active Directory deployments, the vulnerability could be exploited remotely by leveraging the operating system remote management tools. This vulnerability is fixed in Cisco Webex Meetings Desktop App Release 33.6.6 and 33.9.1 releases. This vulnerability is fixed in Cisco Webex Productivity Tools Release 33.0.7.

Una vulnerabilidad en el servicio de actualización de la aplicación de escritorio de Cisco Webex Meetings y Cisco Webex Productivity Tools para Windows podría permitir a un atacante local autenticado ejecutar comandos arbitrarios del sistema operativo como un usuario privilegiado. Esta vulnerabilidad se debe a una validación insuficiente de los parámetros proporcionados por el usuario. Un atacante podría explotar esta vulnerabilidad invocando el comando de actualización de servicio con un argumento manipulado. Un exploit podría permitir que el atacante ejecute comandos arbitrarios con privilegios del usuario SYSTEM. Cuando la métrica de vector de ataque CVSS indica el requisito que necesita un atacante para tener acceso local, los administradores deberían ser conscientes de que en los despliegues de Active Directory, la vulnerabilidad puede explotarse de manera remota, aprovechando las herramientas remotas de gestión del sistema operativo. Esta vulnerabilidad se soluciona en la aplicación de escritorio de Cisco Webex Meetings, en las distribuciones 33.6.6 y 33.9.1. Esta vulnerabilidad se soluciona en Cisco Webex Productivity Tools, en la distribución 33.0.7.

A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow a local attacker to elevate privileges. Cisco Webex Meetings Desktop App versions 33.6.4.15, 33.6.5.2, 33.7.0.694, 33.7.1.15, 33.7.2.24, 33.7.3.7, 33.8.0.779, 33.8.1.13, and 33.8.2.7 are affected.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2018-12-06 CVE Reserved
  • 2019-02-28 CVE Published
  • 2024-07-20 EPSS Updated
  • 2024-11-20 CVE Updated
  • 2024-11-20 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Webex Meetings
Search vendor "Cisco" for product "Webex Meetings"
< 33.6.6
Search vendor "Cisco" for product "Webex Meetings" and version " < 33.6.6"
desktop
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Cisco
Search vendor "Cisco"
Webex Meetings Online
Search vendor "Cisco" for product "Webex Meetings Online"
t33.0.5
Search vendor "Cisco" for product "Webex Meetings Online" and version "t33.0.5"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Cisco
Search vendor "Cisco"
Webex Meetings Online
Search vendor "Cisco" for product "Webex Meetings Online"
t33.6.0
Search vendor "Cisco" for product "Webex Meetings Online" and version "t33.6.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Cisco
Search vendor "Cisco"
Webex Meetings Online
Search vendor "Cisco" for product "Webex Meetings Online"
t33.6.1
Search vendor "Cisco" for product "Webex Meetings Online" and version "t33.6.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Cisco
Search vendor "Cisco"
Webex Meetings Online
Search vendor "Cisco" for product "Webex Meetings Online"
t33.6.2
Search vendor "Cisco" for product "Webex Meetings Online" and version "t33.6.2"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Cisco
Search vendor "Cisco"
Webex Productivity Tools
Search vendor "Cisco" for product "Webex Productivity Tools"
>= 32.6.0 < 33.0.7
Search vendor "Cisco" for product "Webex Productivity Tools" and version " >= 32.6.0 < 33.0.7"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe