cbcvebase.
CVE-2018-0379
published 2018-07-18

CVE-2018-0379: Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An…

PriorityP341high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.81%
76.1th percentile
Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via email or URL and convincing the user to launch the file in the Webex recording players. Exploitation of these vulnerabilities could allow arbitrary code execution on the system of a targeted user. These vulnerabilities affect ARF and WRF recording players available from Cisco Webex Meetings Suite sites, Cisco Webex Meetings Online sites, and Cisco Webex Meetings Server. Cisco Bug IDs: CSCvi02621, CSCvi02965, CSCvi63329, CSCvi63333, CSCvi63335, CSCvi63374, CSCvi63376, CSCvi63377, CSCvi63391, CSCvi63392, CSCvi63396, CSCvi63495, CSCvi63497, CSCvi63498, CSCvi82684, CSCvi82700, CSCvi82705, CSCvi82725, CSCvi82737, CSCvi82742, CSCvi82760, CSCvi82771, CSCvj51284, CSCvj51294.

Affected

12 ranges
VendorProductVersion rangeFixed in
ciscowebex_business_suite
ciscowebex_business_suite
ciscowebex_business_suite
ciscowebex_business_suite
ciscowebex_business_suite
ciscowebex_business_suite31.0 – 31.23
ciscowebex_business_suite>= 32.0 < 32.1532.15
ciscowebex_business_suite33.0 – 33.2
ciscowebex_meeting_server
ciscowebex_meetings_online< 1.3.351.3.35
ciscowebex_meetings_online
ciscowebex_network_recording_players

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.