Remote Code Execution Vulnerability in Cisco WebEx Network Recording Player
CVE-2018-0264

9.6CRITICAL

Key Information:

Vendor
Cisco
Vendor
CVE Published:
2 May 2018

Summary

A vulnerability exists in the Cisco WebEx Network Recording Player that may allow an unauthenticated remote attacker to execute arbitrary code. By sending a maliciously crafted Advanced Recording Format (ARF) file via link or email attachment, and persuading the target user to open the file, attackers could gain control over the user’s system. This impacts various versions of Cisco WebEx Business Suite, Meetings, and Meetings Server, highlighting the importance of maintaining updated software to mitigate security risks.

Affected Version(s)

Cisco WebEx Advanced Recording Format file players Cisco WebEx Advanced Recording Format file players

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.