CVE-2017-6669
Last modified
CVE-2017-6669 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious ARF file via email or URL and convincing the user to launch the file.
Description
Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious ARF file via email or URL and convincing the user to launch the file. Exploitation of these vulnerabilities could cause an affected player to crash and, in some cases, could allow arbitrary code execution on the system of a targeted user. The Cisco WebEx Network Recording Player is an application that is used to play back WebEx meeting recordings that have been recorded on the computer of an online meeting attendee. The player can be automatically installed when the user accesses a recording file that is hosted on a WebEx server. The following client builds are affected by this vulnerability: Cisco WebEx Business Suite (WBS29) client builds prior to T29.13.130, Cisco WebEx Business Suite (WBS30) client builds prior to T30.17, Cisco WebEx Business Suite (WBS31) client builds prior to T31.10. Cisco Bug IDs: CSCvc47758 CSCvc51227 CSCvc51242.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Webex Advanced Recording Format Player | 29.10 |
References
- http://www.securityfocus.com/bid/99196Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038737Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/99196Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038737Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-6669?
How severe is CVE-2017-6669?
How do I fix CVE-2017-6669?
Are you affected by CVE-2017-6669?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
