CVE-2018-0438: Cisco Umbrella Enterprise Roaming Client Privilege Escalation Vulnerability
A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vulnerability is due to improper implementation of file system permissions, which could allow non-administrative users to place files within restricted directories. An attacker could exploit this vulnerability by placing an executable file within the restricted directory, which when executed by the ERC client, would run with Administrator privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0438?
The severity of CVE-2018-0438 is classified as high due to its potential for privilege escalation.
How can CVE-2018-0438 be exploited?
CVE-2018-0438 can be exploited by an authenticated, local attacker using valid local user credentials to elevate their privileges.
What software versions are affected by CVE-2018-0438?
CVE-2018-0438 affects the Cisco Umbrella Enterprise Roaming Client versions prior to 2.1.127.
How do I fix CVE-2018-0438?
To fix CVE-2018-0438, update the Cisco Umbrella Enterprise Roaming Client to version 2.1.127 or later.
Are there any mitigating factors for CVE-2018-0438?
Mitigating factors for CVE-2018-0438 include ensuring that access to vulnerable systems is restricted to trusted users only.