CVE-2017-12372
published 2017-11-30CVE-2017-12372: A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF)…
PriorityP355critical9.6CVSS 3.0
AVNACLPRNUIRSCCHIHAH
EPSS
2.98%
85.8th percentile
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file. Exploitation of this could cause an affected player to crash and, in some cases, could allow arbitrary code execution on the system of a targeted user. Cisco Bug IDs: CSCvf57234, CSCvg54868, CSCvg54870.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings | — | — |
| cisco | webex_meetings | — | — |
| cisco | webex_meetings | — | — |
| cisco | webex_meetings_server | — | — |
| cisco | webex_meetings_server | — | — |
| cisco | webex_recording_format_and_advanced_recording_format_players | — | — |
CVSS provenance
nvdv3.09.6CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco WebEx Recording Format and Advanced Recording Format Players
vendor_cisco·2017-11-30·CVSS 9.6
CVE-2017-12367 [CRITICAL] CWE-119 Multiple Vulnerabilities in Cisco WebEx Recording Format and Advanced Recording Format Players
Multiple Vulnerabilities in Cisco WebEx Recording Format and Advanced Recording Format Players
Multiple vulnerabilities exist in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit these vulnerabilities by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file. Exploitation of these vulnerabilities could cause an affected player to crash and, in some cases, could allow arbitrary code execution on the system of a targeted user.
The Cisco WebEx players are applications that are used to play back WebEx meeting recordings that have been recorded by an online meeting attendee. The player can be automatically installed when the user accesses a reco
Cisco
Multiple Vulnerabilities in Cisco WebEx Recording Format and Advanced Recording Format Players
vendor_cisco·CVSS 3.0
CVE-2017-12372 Multiple Vulnerabilities in Cisco WebEx Recording Format and Advanced Recording Format Players
CVE-2017-12372: Multiple Vulnerabilities in Cisco WebEx Recording Format and Advanced Recording Format Players
Multiple vulnerabilities exist in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit these vulnerabilities by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file. Exploitation of these vulnerabilities could cause an affected player to crash and, in some cases, could allow arbitrary code execution on the system of a targeted user. The Cisco WebEx players are applications that are used to play back WebEx meeting recordings that have been recorded by an online meeting attendee. The player can be automatically installed when the user a
GHSA
GHSA-mjw9-984c-83g9: A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording For
ghsa_unreviewed·2022-05-13
CVE-2017-12372 [CRITICAL] CWE-119 GHSA-mjw9-984c-83g9: A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording For
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file. Exploitation of this could cause an affected player to crash and, in some cases, could allow arbitrary code execution on the system of a targeted user. Cisco Bug IDs: CSCvf57234, CSCvg54868, CSCvg54870.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/102017http://www.securitytracker.com/id/1039895https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-webex-playershttp://www.securityfocus.com/bid/102017http://www.securitytracker.com/id/1039895https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-webex-players
2017-11-30
Published