{ "id": "CVE-2018-15437", "sourceIdentifier": "ykramarz@cisco.com", "published": "2018-11-08T17:29:00.560", "lastModified": "2020-09-16T14:13:03.323", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Windows could allow a local attacker to disable the scanning functionality of the product. This could allow executable files to be launched on the system without being analyzed for threats. The vulnerability is due to improper process resource handling. An attacker could exploit this vulnerability by gaining local access to a system running Microsoft Windows and protected by Cisco Immunet or Cisco AMP for Endpoints and executing a malicious file. A successful exploit could allow the attacker to prevent the scanning services from functioning properly and ultimately prevent the system from being protected from further intrusion." }, { "lang": "es", "value": "Una vulnerabilidad en el componente de escaneo de sistemas Cisco Immunet y Cisco Advanced Malware Protection (AMP) for Endpoints que se ejecuten en Microsoft Windows podr\u00eda permitir que un atacante local deshabilite la funcionalidad de escaneo del producto. Esto podr\u00eda permitir que los archivos ejecutables se lancen en el sistema sin que se analicen en busca de amenazas. Esta vulnerabilidad se debe a la manipulaci\u00f3n incorrecta de los recursos de los procesos. Un atacante podr\u00eda explotar esta vulnerabilidad obteniendo acceso local a un sistema que se ejecute en Microsoft Windows y que est\u00e9 protegido por Cisco Immunet o Cisco AMP for Endpoints y ejecutando un archivo malicioso. Su explotaci\u00f3n con \u00e9xito podr\u00eda permitir que el atacante evite que los servicios de escaneo funcionen correctamente y finalmente evitar que el sistema est\u00e9 protegido contra futuras intrusiones." } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE", "baseScore": 5.5, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 1.8, "impactScore": 3.6 } ], "cvssMetricV30": [ { "source": "ykramarz@cisco.com", "type": "Secondary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseScore": 5.5, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 1.8, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 2.1 }, "baseSeverity": "LOW", "exploitabilityScore": 3.9, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-400" } ] }, { "source": "ykramarz@cisco.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-400" } ] } ], "configurations": [ { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:cisco:advanced_malware_protection_for_endpoints:-:*:*:*:*:*:*:*", "matchCriteriaId": "7EE173FA-23EB-4046-8FE3-1C136713F44C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cisco:immunet_for_endpoints:-:*:*:*:*:*:*:*", "matchCriteriaId": "C12B9E16-1154-4A68-8043-7F87991D31B5" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*", "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA" } ] } ] } ], "references": [ { "url": "http://www.securityfocus.com/bid/105867", "source": "ykramarz@cisco.com", "tags": [ "Third Party Advisory", "VDB Entry" ] }, { "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-imm-dos", "source": "ykramarz@cisco.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://www.exploit-db.com/exploits/45829/", "source": "ykramarz@cisco.com", "tags": [ "Exploit", "Third Party Advisory", "VDB Entry" ] } ] }