Cisco WebEx productitools Privilege Escalation Vulnerability (CVE-2016-4349)
Cisco WebEx productitools Privilege Escalation Vulnerability (CVE-2016-4349)
Release date:
Updated on:
Affected Systems:
Cisco WebEx productitools 2.40.5001.10012
Description:
CVE (CAN) ID: CVE-2016-4349
Cisco WebEx productitools is a WebEx network conferencing tool set.
Cisco WebEx productitools 2.40.5001.10012 has the suspicious search PATH Vulnerability. Use the trojan file cryptsp in the current active directory. dll, dwmapi. dll, msimg32.dll, ntmarta. dll, propsys. dll, riched20.dll, rpcrtremote. dll, secur32.dll, sxs. dll, uxtheme. dll. Local Users can obtain the upgraded permissions.
<* Source: Cisco
*>
Suggestion:
Vendor patch:
Cisco
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Https://www.webex.com/support/productivity-tools.html
Refer:
Https://www.solutionary.com/threat-intelligence/vulnerability-disclosures/2016/04/webex-productivity-tools/
This article permanently updates the link address: