CVE-2018-15442 is a high-severity vulnerability affecting the update service of Cisco Webex Meetings Desktop App for Windows and Cisco Webex Productivity Tools. It allows an authenticated, local attacker to execute arbitrary commands with SYSTEM privileges due to insufficient validation of user-supplied parameters. While primarily a local attack, it can be exploited remotely in Active Directory environments using remote management tools. The vulnerability has a CVSS score of 7.8, indicating high impact on confidentiality, integrity, and availability. Although not on the KEV catalog, multiple Metasploit modules exist, and it has garnered significant community discussion and media coverage, suggesting a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 33.6.4CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_desktop:*:*:*:*:*:windows:*:* | ||
>= 32.6.0, < 33.0.6CPE matchmatch criteria | cpe:2.3:a:cisco:webex_productivity_tools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.