Insecure DLL loading in Cisco Systems, Inc products - CVE-2021-1536
Published: June 3, 2021
Vulnerability identifier: #VU53759
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1536
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to incorrect handling of directory paths at run time. A local user can place a specially crafted .dll file and execute arbitrary code on victim's system.
Affected software
Cisco WebEx Meetings Server
Cisco Webex Meetings Client for Windows
Cisco Webex Teams
Cisco WebEx Network Recording Player
Cisco Webex Meetings Client for Windows
Cisco Webex Teams
Cisco WebEx Network Recording Player
How to mitigate CVE-2021-1536
Install updates from vendor's website.
Cisco WebEx Meetings Server - addressed in versions 3.0 MR4, 4.0 MR4
Cisco Webex Meetings Client for Windows - addressed in versions 41.1.5.11, 41.2.9.23
Cisco WebEx Network Recording Player - addressed in versions 41.1.5.11, 41.2.9.23
Cisco Webex Teams - addressed in versions 41.3.0.18986, 41.4.0.18737, 41.5.0.18815
Cisco Webex Meetings Client for Windows - addressed in versions 41.1.5.11, 41.2.9.23
Cisco WebEx Network Recording Player - addressed in versions 41.1.5.11, 41.2.9.23
Cisco Webex Teams - addressed in versions 41.3.0.18986, 41.4.0.18737, 41.5.0.18815