Vulnslist

find the latest Cisco vulnerabilities

Cisco Umbrella Roaming Client for Windows Install Vulnerability

cisco-sa-20200122-umbrella-msi-install · Medium · Published · Updated

A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted device. The vulnerability is due to insufficient verification of the Windows Installer. An attacker could exploit this vulnerability by placing a file in a specific location in the Windows file system. A successful exploit could allow the attacker to bypass configured policy and install unapproved applications. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200122-umbrella-msi-install

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2019-16000
Cisco Bug IDsCSCvr39895
CVSS ScoreBase 4.4
Base 4.4 CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Umbrella Enterprise Roaming Client for Windows

Related Products

Product CVE Evidence