Vulnerability Description
Untrusted search path vulnerability in Cisco WebEx Productivity Tools 2.40.5001.10012 allows local users to gain privileges via a Trojan horse cryptsp.dll, dwmapi.dll, msimg32.dll, ntmarta.dll, propsys.dll, riched20.dll, rpcrtremote.dll, secur32.dll, sxs.dll, or uxtheme.dll file in the current working directory, aka Bug ID CSCuy56140.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Webex Productivity Tools | 2.40.5001.10012 |
References
- https://www.solutionary.com/threat-intelligence/vulnerability-disclosures/2016/0
- https://www.solutionary.com/threat-intelligence/vulnerability-disclosures/2016/0
FAQ
What is CVE-2016-4349?
CVE-2016-4349 is a vulnerability with a CVSS score of 7.8 (HIGH). Untrusted search path vulnerability in Cisco WebEx Productivity Tools 2.40.5001.10012 allows local users to gain privileges via a Trojan horse cryptsp.dll, dwmapi.dll, msimg32.dll, ntmarta.dll, propsy...
How severe is CVE-2016-4349?
CVE-2016-4349 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4349?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Webex Productivity Tools.