漏洞信息详情
Cisco Webex Meetings Desktop App和Cisco Webex Productivity Tools 操作系统命令注入漏洞
漏洞简介
Cisco Webex Meetings Desktop App和Cisco Webex Productivity Tools都是美国思科(Cisco)公司的产品。Cisco Webex Meetings Desktop App是一款使用在桌面环境上的视频会议控制应用程序。Cisco Webex Productivity Tools是一款视频会议调度工具。
基于Windows平台的Cisco Webex Meetings Desktop App 33.6.6之前版本和Cisco Webex Productivity Tools 32.6.0版本至33.0.7之前版本中的更新服务存在操作系统命令注入漏洞,该漏洞源于程序没有充分地验证用户提交的参数。本地攻击者可借助特制的参数调用更新服务命令利用该漏洞以SYSTEM用户权限运行任意命令。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-wmda-cmdinj
参考网址
来源:CISCO
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-wmda-cmdinj
来源:BID
链接:https://www.securityfocus.com/bid/107184
来源:www.exploit-db.com
链接:https://www.exploit-db.com/exploits/46479/
来源:www.securityfocus.com
链接:http://www.securityfocus.com/bid/107184
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/151914/Cisco-WebEx-Meetings-Privilege-Escalation.html
来源:www.nsfocus.net
链接:http://www.nsfocus.net/vulndb/42826
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-wmda-cmdinj
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/76234
来源:www.exploit-db.com
链接:https://www.exploit-db.com/exploits/46479
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-1674
受影响实体
暂无
补丁
- Cisco Webex Meetings Desktop App和Cisco Webex Productivity Tools 操作系统命令注入漏洞的修复措施<!--2019-2-27-->
还没有评论,来说两句吧...