Back

CVE-2018-6968

CRITICAL

The VMware AirWatch Agent for Android prior to 8.2 and AirWatch Agent for Windows Mobile prior to 6.5.2 contain a remote code execution vulnerability in real time File Manager capabilities. This vulnerability may allow for unauthorized creation and execution of files in the Agent sandbox and other publicly accessible directories such as those on the SD card by a malicious administrator.

Published: Jun 11, 2018 Modified: Jun 17, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
vmware airwatch_agent * < 6.5.2
vmware airwatch_agent * < 8.2

GitHub Security Advisory GHSA-pf3f-28gw-f274

The VMware AirWatch Agent for Android prior to 8.2 and AirWatch Agent for Windows Mobile prior to...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 5.00%

Top 8% most likely to be exploited

Threat Score 41.5 / 100

Data Sources

NVD EPSS GitHub