Remote Code Execution Flaw in Cisco WebEx Network Recording Player
CVE-2017-12371

9.6CRITICAL

Key Information:

Vendor
Cisco
Vendor
CVE Published:
30 November 2017

Summary

A vulnerability in the Cisco WebEx Network Recording Player allows remote code execution through malicious ARF and WRF files. Attackers can exploit this by sending a user a compromised file via email or through a URL. Once the user opens the file, it may lead to crashes in the WebEx player and potentially allow the attacker to execute arbitrary code on the user's system. This poses significant risks to user security and system integrity, as unauthorized access may compromise sensitive data and resources.

Affected Version(s)

Cisco WebEx Recording Format and Advanced Recording Format Players Cisco WebEx Recording Format and Advanced Recording Format Players

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.