Insecure DLL loading in Cisco Systems, Inc products - CVE-2021-1536

 

Insecure DLL loading in Cisco Systems, Inc products - CVE-2021-1536

Published: June 3, 2021


Vulnerability identifier: #VU53759
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1536
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists due to incorrect handling of directory paths at run time. A local user can place a specially crafted .dll file and execute arbitrary code on victim's system.


Affected software

Cisco WebEx Meetings Server
Cisco Webex Meetings Client for Windows
Cisco Webex Teams
Cisco WebEx Network Recording Player

How to mitigate CVE-2021-1536

Install updates from vendor's website.

Cisco WebEx Meetings Server - addressed in versions 3.0 MR4, 4.0 MR4
Cisco Webex Meetings Client for Windows - addressed in versions 41.1.5.11, 41.2.9.23
Cisco WebEx Network Recording Player - addressed in versions 41.1.5.11, 41.2.9.23
Cisco Webex Teams - addressed in versions 41.3.0.18986, 41.4.0.18737, 41.5.0.18815

External References

Related Security Bulletins