CVE-2016-1464 describes a critical arbitrary code execution vulnerability in Cisco WebEx Meetings Player T29.10 when WRF file support is enabled. An attacker could exploit this by tricking a user into opening a specially crafted WRF file. With a CVSS score of 7.8 (High), this vulnerability allows for complete compromise of confidentiality, integrity, and availability on the affected system, requiring user interaction but with low attack complexity. While not listed on the KEV catalog, public exploit code exists on ExploitDB, and it has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
sp10_baseCPE matchmatch criteria | cpe:2.3:a:cisco:webex_wrf_player_t29:sp10_base:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.