Out-of-Bounds Vulnerability in Cisco WebEx Network Recording Player
CVE-2017-12369

9.6CRITICAL

Key Information:

Vendor
Cisco
Vendor
CVE Published:
30 November 2017

Summary

The vulnerability in Cisco WebEx Network Recording Player pertains to its processing of Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker may exploit this vulnerability by sending crafted ARF or WRF files through email or a URL link. If a user unknowingly launches these malicious file types, it could lead to crashing the player and may enable arbitrary code execution on the user's system. Users are advised to exercise caution and ensure software is up to date to mitigate potential risks.

Affected Version(s)

Cisco WebEx Recording Format and Advanced Recording Format Players Cisco WebEx Recording Format and Advanced Recording Format Players

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.