CVE-2021-1503 is a high-severity vulnerability affecting Cisco Webex Network Recording Player and Cisco Webex Player for Windows and MacOS. It allows for arbitrary code execution due to insufficient validation of ARF or WRF recording files. An attacker could exploit this by tricking a user into opening a malicious file, leading to code execution with the user's privileges. While the CVSS score is 7.8 (High), indicating a significant risk, there is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable. Despite this, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:4.0:-:*:*:*:*:*:* | ||
< 41.2CPE matchmatch criteria | cpe:2.3:a:cisco:webex_player:*:*:*:*:*:macos:*:* | ||
< 41.2CPE matchmatch criteria | cpe:2.3:a:cisco:webex_player:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.