Vulnslist

find the latest Cisco vulnerabilities

Cisco Webex Network Recording Player Arbitrary Code Execution Vulnerabilities

cisco-sa-20190515-webex-player · High · Published · Updated

Multiple vulnerabilities in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file via a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system.  Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. No exploit code proving exploitability of the vulnerabilities is publicly available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-webex-player

Workarounds

There are no workarounds that address these vulnerabilities. However, customers may remove the Cisco Webex Network Recording Player and the Cisco Webex Player from a system by using the software-removal procedure for the operating system. For example, to remove a player from a Microsoft Windows 10 system, customers can use the Apps & Features app in Windows Settings.

To remove all Cisco Webex software from a Microsoft Windows system, customers can use the Meeting Services Removal Tool, which is available for download from the Cisco Collaboration Help article Cisco Webex and 3rd Party Support Utilities https://collaborationhelp.cisco.com/article/en-us/WBX000026396 .

By removing the Cisco Webex Network Recording Player, a user will be unable to play recordings. However, the next time media is accessed, the system will download a new version of the software, providing the user with an updated version.

CVEsCVE-2019-1771, CVE-2019-1772, CVE-2019-1773
Cisco Bug IDsCSCvn88721, CSCvo03346, CSCvo05231, CSCvo05229, CSCvo33767, CSCvo33769, CSCvo33774
CVSS ScoreBase 7.8
Base 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco WebEx WRF Player, Cisco WebEx ARF Player

Related Products

Product CVE Evidence
Cisco Webex Network Recording Player CVE-2019-1773 Cisco OpenVuln
Cisco Webex Network Recording Player CVE-2019-1772 Cisco OpenVuln
Cisco Webex Network Recording Player CVE-2019-1771 Cisco OpenVuln
Cisco WebEx WRF Player CVE-2019-1773 Cisco OpenVuln
Cisco WebEx WRF Player CVE-2019-1772 Cisco OpenVuln
Cisco WebEx WRF Player CVE-2019-1771 Cisco OpenVuln
Cisco WebEx ARF Player CVE-2019-1773 Cisco OpenVuln
Cisco WebEx ARF Player CVE-2019-1772 Cisco OpenVuln
Cisco WebEx ARF Player CVE-2019-1771 Cisco OpenVuln