vendor:
Umbrella Roaming Client
by:
paragonsec @ Critical Start
7.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Umbrella Roaming Client
Affected Version From: 2.0.168
Affected Version To: 2.0.168
Patch Exists: NO
Related CWE: CVE-2018-0437, CVE-2018-0438
CPE: a:cisco:umbrella_roaming_client:2.0.168
Platforms Tested: Windows 10 Professional
2018
Cisco Umbrella Roaming Client 2.0.168 – Privilege Escalation
Compile the following code and rename it to either netsh.exe or cmd.exe and place the file in the 'C:ProgramDataOpenDNSERC' directory. Restart the machine! Create malicious MSI file named RoamingClient_WIN_2.0.168.msi and place in 'C:ProgramDataOpenDNSERCUpgrades' and restart the machine.
Mitigation:
Unknown