CVE-2018-0379
published 2018-07-18CVE-2018-0379: Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An…
PriorityP341high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.81%
76.1th percentile
Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via email or URL and convincing the user to launch the file in the Webex recording players. Exploitation of these vulnerabilities could allow arbitrary code execution on the system of a targeted user. These vulnerabilities affect ARF and WRF recording players available from Cisco Webex Meetings Suite sites, Cisco Webex Meetings Online sites, and Cisco Webex Meetings Server. Cisco Bug IDs: CSCvi02621, CSCvi02965, CSCvi63329, CSCvi63333, CSCvi63335, CSCvi63374, CSCvi63376, CSCvi63377, CSCvi63391, CSCvi63392, CSCvi63396, CSCvi63495, CSCvi63497, CSCvi63498, CSCvi82684, CSCvi82700, CSCvi82705, CSCvi82725, CSCvi82737, CSCvi82742, CSCvi82760, CSCvi82771, CSCvj51284, CSCvj51294.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_business_suite | — | — |
| cisco | webex_business_suite | — | — |
| cisco | webex_business_suite | — | — |
| cisco | webex_business_suite | — | — |
| cisco | webex_business_suite | — | — |
| cisco | webex_business_suite | 31.0 – 31.23 | — |
| cisco | webex_business_suite | >= 32.0 < 32.15 | 32.15 |
| cisco | webex_business_suite | 33.0 – 33.2 | — |
| cisco | webex_meeting_server | — | — |
| cisco | webex_meetings_online | < 1.3.35 | 1.3.35 |
| cisco | webex_meetings_online | — | — |
| cisco | webex_network_recording_players | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Webex Network Recording Players Remote Code Execution Vulnerabilities
vendor_cisco·2018-07-18·CVSS 7.8
CVE-2018-0379 [HIGH] CWE-119 Cisco Webex Network Recording Players Remote Code Execution Vulnerabilities
Cisco Webex Network Recording Players Remote Code Execution Vulnerabilities
Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via email or URL and convincing the user to launch the file in the Webex recording players. Exploitation of these vulnerabilities could allow arbitrary code execution on the system of a targeted user. There is no risk when a .arf player that is stored on a Webex site is played in the Webex Network Recording Player.
The Cisco Webex players are applications that are used to play back Webex meetings that have been recorded by an online meeting attendee. The Webex Netw
Cisco
Cisco Webex Network Recording Players Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2018-0379 Cisco Webex Network Recording Players Remote Code Execution Vulnerabilities
CVE-2018-0379: Cisco Webex Network Recording Players Remote Code Execution Vulnerabilities
Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via email or URL and convincing the user to launch the file in the Webex recording players. Exploitation of these vulnerabilities could allow arbitrary code execution on the system of a targeted user. There is no risk when a .arf player that is stored on a Webex site is played in the Webex Network Recording Player. The Cisco Webex players are applications that are used to play back Webex meetings that have been recorded by an online meeting attendee.
GHSA
GHSA-w494-3p63-x3xx: Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files
ghsa_unreviewed·2022-05-13
CVE-2018-0379 [HIGH] CWE-119 GHSA-w494-3p63-x3xx: Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files
Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via email or URL and convincing the user to launch the file in the Webex recording players. Exploitation of these vulnerabilities could allow arbitrary code execution on the system of a targeted user. These vulnerabilities affect ARF and WRF recording players available from Cisco Webex Meetings Suite sites, Cisco Webex Meetings Online sites, and Cisco Webex Meetings Server. Cisco Bug IDs: CSCvi02621, CSCvi02965, CSCvi63329, CSCvi63333, CSCvi63335, CSCvi63374, CSCvi63376, CSCvi63377, CSCvi63391, CSCvi63392, CSCvi63396, CSCvi63495, CSCvi63497
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/104853http://www.securitytracker.com/id/1041347https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180718-webex-rcehttp://www.securityfocus.com/bid/104853http://www.securitytracker.com/id/1041347https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180718-webex-rce
2018-07-18
Published