Arbitrary Code Execution Vulnerabilities in Cisco Webex Recording Players
CVE-2018-0379

7.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
18 July 2018

Summary

Multiple security vulnerabilities are present in the Cisco Webex Network Recording Player, specifically affecting the playback of Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. These vulnerabilities can be exploited when a user is tricked into opening a maliciously crafted .arf or .wrf file. Successful exploitation could enable attackers to execute arbitrary code on the user's system, potentially compromising their security and data integrity. This issue impacts users of Cisco's Webex Meetings products, making it critical for users to ensure they are protected against such threats.

Affected Version(s)

Cisco Webex Network Recording Players unknown Cisco Webex Network Recording Players unknown

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.