CVE-2018-6968 describes a critical remote code execution vulnerability in VMware AirWatch Agent for Android (prior to 8.2) and AirWatch Agent for Windows Mobile (prior to 6.5.2). This flaw allows a malicious administrator to remotely create and execute files within the Agent's sandbox or other publicly accessible directories. With a CVSS score of 10.0 (CRITICAL), this vulnerability is easily exploitable over the network with low complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code is currently available and it is not listed on the KEV catalog, its high severity and potential for significant impact warrant attention, as evidenced by limited media coverage and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5.2CPE matchmatch criteria | cpe:2.3:a:vmware:airwatch_agent:*:*:*:*:*:windows_mobile:*:* | ||
< 8.2CPE matchmatch criteria | cpe:2.3:a:vmware:airwatch_agent:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.