PT-2018-1193 · Cisco · Cisco Webex Meetings+3

Published

2018-05-02

·

Updated

2019-10-09

·

CVE-2018-0264

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco WebEx Business Suite versions prior to T31.23.4 Cisco WebEx Business Suite versions prior to T32.12 Cisco WebEx Meetings versions prior to T32.12 Cisco WebEx Meetings Server versions prior to 3.0 Patch 1
Description A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. This is due to insufficient input validation in the ARF file processing mechanism. An attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and persuading the user to follow the link or open the file. Successful exploitation could allow the attacker to execute arbitrary code on the user's system.
Recommendations For Cisco WebEx Business Suite versions prior to T31.23.4, update to version T31.23.4 or later. For Cisco WebEx Business Suite versions prior to T32.12, update to version T32.12 or later. For Cisco WebEx Meetings versions prior to T32.12, update to version T32.12 or later. For Cisco WebEx Meetings Server versions prior to 3.0 Patch 1, apply Patch 1 or later. As a temporary workaround, consider disabling the ARF file playback feature until a patch is available. Restrict access to ARF files from untrusted sources to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00651
CVE-2018-0264

Affected Products

Cisco Webex Business Suite
Cisco Webex Meetings
Cisco Webex Meetings Server
Cisco Webex Network Recording Player