CVE-2018-0379

CWE-119Buffer Overflow5 documents5 sources
Severity
7.8HIGH
EPSS
0.4%
top 38.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateMay 13

Description

Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via email or URL and convincing the user to launch the file in the Webex recording players. Exploitation of these vulnerabilities could allow arbitrary code execution on the system of a targeted user. These vulnerabilities affect ARF and WRF reco

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5cisco_webex_network_recording_players_unknownCisco Webex Network Recording Players unknown
NVDcisco/webex_business_suite32.032.15+7

🔴Vulnerability Details

2
GHSA
GHSA-w494-3p63-x3xx: Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files2022-05-13
CVEList
CVE-2018-0379: Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files2018-07-18

📋Vendor Advisories

1
Cisco
Cisco Webex Network Recording Players Remote Code Execution Vulnerabilities2018-07-18

💬Community

1
Bugzilla
CVE-2018-0764 .NET Core: Improper processing of XML documents can cause a denial of service2018-01-12
CVE-2018-0379 (HIGH CVSS 7.8) | Multiple vulnerabilities exist in t | cvebase.io