CVE-2017-12372 is a critical remote code execution vulnerability affecting Cisco WebEx Network Recording Player for ARF and WRF files, impacting Cisco WebEx Meetings and WebEx Meetings Server. This vulnerability, with a CVSS score of 9.6, can be exploited by a remote attacker convincing a user to open a malicious file, leading to system crashes or arbitrary code execution. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in KEV, it garnered some community discussion and media coverage at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:2.6:*:*:*:*:*:*:* | ||
2.7CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:2.7:*:*:*:*:*:*:* | ||
t29CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings:t29:*:*:*:*:*:*:* | ||
t30CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings:t30:*:*:*:*:*:*:* | ||
t31.11.2CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings:t31.11.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.