CVE-2018-0422 describes a vulnerability in Cisco Webex Meetings client for Windows, where improper folder permissions allow an authenticated, local attacker to modify local files and execute code. This vulnerability has a CVSS score of 7.3 (High), indicating that a low-privileged local attacker can achieve high impact on confidentiality, integrity, and availability with low attack complexity, though user interaction is required. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.37CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:*:*:*:*:*:*:*:* | ||
t31.20CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:t31.20:*:*:*:*:*:*:* | ||
t31.20.2CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:t31.20.2:*:*:*:*:*:*:* | ||
<= 3.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:3.0:mr1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.