PT-2021-3266 · Cisco · Cisco Webex Player

Kushal Arvind Shah

·

Published

2021-06-02

·

Updated

2021-06-14

·

CVE-2021-1527

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Webex Player for Windows and MacOS (affected versions not specified)
Description A vulnerability in Cisco Webex Player could allow an attacker to cause the software to terminate or gain access to memory state information related to the application. This is due to insufficient validation of values in Webex recording files stored in Webex Recording Format (WRF). An attacker could exploit this by sending a malicious WRF file to a user and persuading them to open it with the affected software, potentially crashing the software and allowing access to memory state information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03006
CVE-2021-1527

Affected Products

Cisco Webex Player