cisco-sa-20161207-hms
Cisco Hybrid Media Service Privilege Escalation Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
A vulnerability in the installation procedure of the Cisco Hybrid Media Service could allow an authenticated, local attacker to elevate privileges to the root level. The vulnerability is due to incorrect installation and permissions settings on binary files during the Hybrid Media Service installation procedure. An attacker could exploit this vulnerability by logging in to the device and elevating privileges. A successful exploit could allow the attacker to acquire root-level privileges and take full control of the device. There are no workarounds that address this vulnerability.
| Product | CVE |
|---|---|
| Cisco Hybrid Meeting Server | CVE-2016-6470 |