header-logo
Suggest Exploit
vendor:
N/A
by:
Jeff McJunkin
7.2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2018-15442
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Windows
2018

WebEx Local Service Permissions Exploit

This module exploits a flaw in the 'webexservice' Windows service, which runs as SYSTEM, can be used to run arbitrary commands locally, and can be started by limited users in default installations.

Mitigation:

Restrict access to the webexservice service to only privileged users.
Source

Exploit-DB raw data: