Improper input validation in Webex Player and Cisco WebEx Network Recording Player - CVE-2018-15409

 

Improper input validation in Webex Player and Cisco WebEx Network Recording Player - CVE-2018-15409

Published: October 3, 2018 / Updated: October 9, 2018


Vulnerability identifier: #VU15179
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15409
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper validation of Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. A remote unauthenticated attacker can trick the victim into opening a specially crafted ARF or WRF file sent via a link or an email attachment and execute arbitrary code

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Webex Player
Cisco WebEx Network Recording Player

How to mitigate CVE-2018-15409

Install update from vendor's website.

Webex Player - addressed in versions 1.3.37, 1.3.38, 1.3.39, 3.0MR2 Patch 1, 3.0MR2, 31.23.0, 31.23.4, 32.15.10, 32.15.20, 32.15.30, 33.3, 33.4, 33.5
Cisco WebEx Network Recording Player - addressed in versions 1.3.37, 1.3.38, 1.3.39, 3.0MR2 Patch 1, 3.0MR2, 31.23.0, 31.23.4, 32.15.10, 32.15.20, 32.15.30, 33.3, 33.4, 33.5

External References

Related Security Bulletins