Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2019-1674— Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools Update Service Command Injection Vulnerability

Quick assessment

Affected
Cisco Cisco Webex Meetings Desktop App
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cisco Webex Meetings Desktop App和Cisco Webex Productivity Tools都是美国思科(Cisco)公司的产品。Cisco Webex Meetings Desktop App是一款使用在桌面环境上的视频会议控制应用程序。Cisco Webex Productivity Tools是一款视频会议调度工具。 基于Windows平台的Cisco Webex Meetings Desktop App 33.6.6之前版本和Cisco Webex Product

AI Predicted 8.8 Difficulty: Moderate EPSS 9.81% · P95

Public Exploits 1

ExploitDB · 1 EDB-46479 [local]
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2019-1674

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools Update Service Command Injection Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by invoking the update service command with a crafted argument. An exploit could allow the attacker to run arbitrary commands with SYSTEM user privileges. While the CVSS Attack Vector metric denotes the requirement for an attacker to have local access, administrators should be aware that in Active Directory deployments, the vulnerability could be exploited remotely by leveraging the operating system remote management tools. This vulnerability is fixed in Cisco Webex Meetings Desktop App Release 33.6.6 and 33.9.1 releases. This vulnerability is fixed in Cisco Webex Productivity Tools Release 33.0.7.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5
Vulnerability Title
Cisco Webex Meetings Desktop App和Cisco Webex Productivity Tools 操作系统命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Webex Meetings Desktop App和Cisco Webex Productivity Tools都是美国思科(Cisco)公司的产品。Cisco Webex Meetings Desktop App是一款使用在桌面环境上的视频会议控制应用程序。Cisco Webex Productivity Tools是一款视频会议调度工具。 基于Windows平台的Cisco Webex Meetings Desktop App 33.6.6之前版本和Cisco Webex Product
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cisco Cisco Webex Meetings Desktop App unspecified ~ 33.6.6 -
Cisco Cisco Webex Productivity Tools unspecified ~ 33.0.7 -

II. Public POCs for CVE-2019-1674

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-1674

请登录查看更多情报信息。

Vendor Advisories for CVE-2019-1674 (2)

Exploits & Public PoCs for CVE-2019-1674 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2019-1674

No comments yet


Leave a comment