HIGH

CVE-2018-15442

CVSS v3

7.8

HIGH

EPSS Score

47.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by invoking the update service command with a crafted argument. An exploit could allow the attacker to run arbitrary commands with SYSTEM user privileges. While the CVSS Attack Vector metric denotes the requirement for an attacker to have local access, administrators should be aware that in Active Directory deployments, the vulnerability could be exploited remotely by leveraging the operating system remote management tools.

Technical details

Published
10/24/2018

Frequently asked questions

What is CVE-2018-15442?

A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by invoking the update service command with a crafted argument. An exploit could allow the attacker to run arbitrary commands with SYSTEM user privileges. While the CVSS Attack Vector metric denotes the requirement for an attacker to have local access, administrators should be aware that in Active Directory deployments, the vulnerability could be exploited remotely by leveraging the operating system remote management tools.

Is CVE-2018-15442 actively exploited?

Active exploitation of CVE-2018-15442 has not been confirmed. The EPSS score is 47.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-15442?

CVE-2018-15442 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2018-15442 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.