First published: Thu Oct 05 2017(Updated: )
A vulnerability in the routine that loads DLL files in Cisco Meeting App for Windows could allow an authenticated, local attacker to run an executable file with privileges equivalent to those of Cisco Meeting App. The vulnerability is due to incomplete input validation of the path name for DLL files before they are loaded. An attacker could exploit this vulnerability by installing a crafted DLL file in a specific system directory. A successful exploit could allow the attacker to execute commands on the underlying Microsoft Windows host with privileges equivalent to those of Cisco Meeting App. The attacker would need valid user credentials to exploit this vulnerability. Cisco Bug IDs: CSCvd77907.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Meetings App |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12266 has been rated as a medium severity vulnerability.
To fix CVE-2017-12266, update the Cisco Meeting App to the latest version provided by Cisco.
CVE-2017-12266 affects users of the Cisco Meeting App for Windows who have the software installed.
CVEs like CVE-2017-12266 can be exploited by an authenticated local attacker to execute arbitrary code.
The main cause of CVE-2017-12266 is the incomplete input validation of the path name for DLL files in the Cisco Meeting App.