CVE-2018-15442 is a privilege escalation vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows. The vulnerability arises from insufficient validation of user-supplied parameters by the update service, which runs with SYSTEM privileges. An authenticated local attacker can exploit this by invoking the update service with crafted arguments, resulting in arbitrary command execution as SYSTEM. In Active Directory environments, remote exploitation is possible via OS remote management tools.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module: 'webexec.rb', which targets Windows systems via the SMB protocol. The exploit leverages the WebExec technique (CVE-2018-15442) to achieve authenticated code execution on Windows hosts. Unlike traditional psexec-style attacks, this module allows any non-guest account to execute arbitrary payloads, making it effective even with low-privilege credentials. The module requires valid SMB credentials and network access to the target's SMB service (typically port 445). Payloads are staged in a specified directory (default: c:\Windows\Temp\) and can be delivered using various stagers (PowerShell, EXE, VBS). The exploit is fully integrated into the Metasploit framework, supporting customizable payloads and automated credential reporting. The code is mature and weaponized, suitable for both proof-of-concept and operational use.
This repository contains a single Metasploit auxiliary module: 'modules/auxiliary/admin/smb/webexec_command.rb'. The module exploits a remote code execution vulnerability (CVE-2018-15442) in Cisco's WebEx client software by leveraging SMB (port 445) to execute arbitrary commands as SYSTEM on the target Windows host. The module requires valid SMB credentials and allows the user to specify any command to run, with the default being the creation of a new user. The code is written in Ruby and is structured as a typical Metasploit module, including option registration and a main 'run_host' method that handles authentication and command execution. The only fingerprintable endpoint is the SMB service on TCP port 445. The exploit is operational and can be used to gain SYSTEM-level access on vulnerable systems.
This repository contains a single Metasploit module (modules/exploits/windows/local/webexec.rb) that exploits a local privilege escalation vulnerability (CVE-2018-15442) in the 'webexservice' Windows service, commonly installed with Cisco WebEx. The exploit works by dropping a malicious executable (Metasploit payload) into a writable directory (default: %SystemRoot%\Temp), then starting the vulnerable service in a way that causes it to execute the payload as SYSTEM. The module includes logic to check for the presence and configuration of the service, validate architecture, and handle payload generation and cleanup. The exploit is operational and provides SYSTEM-level code execution on affected systems. The only endpoints referenced are local file paths and the Windows service name. The code is written in Ruby and is designed to be run within the Metasploit Framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.