Remote Code Execution Vulnerability in Cisco WebEx Network Recording Player
CVE-2017-12370

9.6CRITICAL

Key Information:

Vendor
Cisco
Vendor
CVE Published:
30 November 2017

Summary

A remote code execution vulnerability exists within the Cisco WebEx Network Recording Player that processes Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. An attacker may exploit this vulnerability by enticing the user to download and open a specially crafted ARF or WRF file, potentially leading to the execution of arbitrary code on the user's system. This flaw highlights the importance of user awareness and caution when handling unknown files received via email or downloaded from the internet. For more details, refer to the Cisco security advisory linked below.

Affected Version(s)

Cisco WebEx Recording Format and Advanced Recording Format Players Cisco WebEx Recording Format and Advanced Recording Format Players

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.