CVE-2019-16000

MEDIUM

Cisco Umbrella Roaming Client for Windows - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted device. The vulnerability is due to insufficient verification of the Windows Installer. An attacker could exploit this vulnerability by placing a file in a specific location in the Windows file system. A successful exploit could allow the attacker to bypass configured policy and install unapproved applications.

References (1)

Core 1

Scores

CVSS v3 4.4
EPSS 0.0018
EPSS Percentile 7.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-345
Status published
Products (1)
cisco/umbrella_roaming_client 2.2.238
Published Sep 23, 2020
Tracked Since Feb 18, 2026