漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Cisco Webex Teams for Windows DLL Hijacking Vulnerability
Vulnerability Description
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of the resources loaded by the application at run time. An attacker could exploit this vulnerability by crafting a malicious DLL file and placing it in a specific location on the targeted system. The malicious DLL file would execute when the vulnerable application is launched. A successful exploit could allow the attacker to execute arbitrary code on the target machine with the privileges of another user account.
CVSS Information
N/A
Vulnerability Type
对搜索路径元素未加控制
Vulnerability Title
Cisco Webex Teams 代码问题漏洞
Vulnerability Description
Cisco Webex Teams是美国思科(Cisco)公司的一款团队协作应用程序。该程序包括视频会议、消息群发和文件共享功能。 基于Windows平台的Cisco Webex Teams中存在代码问题漏洞,该漏洞源于程序没有充分验证加载的资源。本地攻击者可借助恶意的DLL文件利用该漏洞以其他用户权限在目标设备上执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A