Remote Code Execution Vulnerability in Cisco WebEx Network Recording Player
CVE-2017-12372
9.6CRITICAL
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 30 November 2017
Summary
A vulnerability in the Cisco WebEx Network Recording Player allows remote attackers to exploit affected systems by providing malicious ARF or WRF files. If a user is convinced to open such a file, it could lead to crashes of the player and potentially allow attackers to execute arbitrary code on the user's system. This vulnerability highlights the risks associated with handling untrusted files and emphasizes the need for robust security practices.
Affected Version(s)
Cisco WebEx Recording Format and Advanced Recording Format Players Cisco WebEx Recording Format and Advanced Recording Format Players
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved