Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities

Related Vulnerabilities: CVE-2018-15408   CVE-2018-15409   CVE-2018-15410   CVE-2018-15411   CVE-2018-15412   CVE-2018-15413   CVE-2018-15415   CVE-2018-15416   CVE-2018-15417   CVE-2018-15418   CVE-2018-15419   CVE-2018-15420   CVE-2018-15431  

Multiple vulnerabilities in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file via a link or an email attachment and persuading the user to open the file by using the affected software. A successful exploit could allow the attacker to execute arbitrary code on the affected system. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-webex-rce