CVE-2016-4349: High severity cisco webex productivity tools vulnerability
Untrusted search path vulnerability in Cisco WebEx Productivity Tools 2.40.5001.10012 allows local users to gain privileges via a Trojan horse cryptsp.dll, dwmapi.dll, msimg32.dll, ntmarta.dll, propsys.dll, riched20.dll, rpcrtremote.dll, secur32.dll, sxs.dll, or uxtheme.dll file in the current working directory, aka Bug ID CSCuy56140.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4349?
CVE-2016-4349 is classified as a medium-severity untrusted search path vulnerability.
How do I fix CVE-2016-4349?
To fix CVE-2016-4349, ensure that the Cisco WebEx Productivity Tools are updated to the latest version.
Who is affected by CVE-2016-4349?
CVE-2016-4349 affects local users of Cisco WebEx Productivity Tools version 2.40.5001.10012.
What types of files are involved in CVE-2016-4349?
CVE-2016-4349 involves potentially malicious versions of specific Windows DLL files.
What can an attacker gain from exploiting CVE-2016-4349?
An attacker exploiting CVE-2016-4349 may gain elevated privileges on the affected system.