Remote Code Execution Vulnerability in Cisco WebEx Network Recording Player
CVE-2018-0264
9.6CRITICAL
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 2 May 2018
Summary
A vulnerability exists in the Cisco WebEx Network Recording Player that may allow an unauthenticated remote attacker to execute arbitrary code. By sending a maliciously crafted Advanced Recording Format (ARF) file via link or email attachment, and persuading the target user to open the file, attackers could gain control over the user’s system. This impacts various versions of Cisco WebEx Business Suite, Meetings, and Meetings Server, highlighting the importance of maintaining updated software to mitigate security risks.
Affected Version(s)
Cisco WebEx Advanced Recording Format file players Cisco WebEx Advanced Recording Format file players
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved