9.3

CVE-2018-15422

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file via a link or an email attachment and persuading the user to open the file by using the affected software. A successful exploit could allow the attacker to execute arbitrary code on the affected system.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoWebex Meetings Online Version < 1.3.37
CiscoWebex Meetings Server Version2.5 Updatemaintenance_release2_patch1
CiscoWebex Meetings Server Version2.5 Updatemaintenance_release5_patch1
CiscoWebex Meetings Server Version2.5 Updatemaintenance_release6_patch2
CiscoWebex Meetings Server Version2.5 Updatemaintenance_release6_patch3
CiscoWebex Meetings Server Version2.5 Updatemaintenance_release6_patch4
CiscoWebex Meetings Server Version2.5.1.29
CiscoWebex Meetings Server Version2.6
CiscoWebex Meetings Server Version2.6 Updatemaintenance_release1_patch1
CiscoWebex Meetings Server Version2.6 Updatemaintenance_release2_patch1
CiscoWebex Meetings Server Version2.6 Updatemaintenance_release3_patch1
CiscoWebex Meetings Server Version2.6 Updatemaintenance_release3_patch2
CiscoWebex Meetings Server Version2.7
CiscoWebex Meetings Server Version2.7 Updatebase
CiscoWebex Meetings Server Version2.7 Updatemaintenance_release1_patch1
CiscoWebex Meetings Server Version2.7 Updatemaintenance_release2_patch1
CiscoWebex Meetings Server Version2.7.1
CiscoWebex Meetings Server Version2.8
CiscoWebex Meetings Server Version2.8 Updatebase
CiscoWebex Business Suite 32 Version < 32.15.10
CiscoWebex Business Suite 33 Version < 33.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.445
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.