CVE-2018-15422 describes a critical vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Windows, affecting Webex Business Suite and Meetings products. This flaw, stemming from improper validation of ARF and WRF files, allows an attacker to execute arbitrary code on a user's system if they open a specially crafted malicious file. Rated 7.8 HIGH, exploitation requires user interaction (UI:R) via a malicious file, but could lead to full compromise (C:H/I:H/A:H). While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not in CISA's KEV catalog, its media coverage and community discussion indicate some awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.37CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:*:*:*:*:*:*:*:* | ||
2.5CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:2.5:maintenance_release2_patch1:*:*:*:*:*:* | ||
2.5CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:2.5:maintenance_release5_patch1:*:*:*:*:*:* | ||
2.5CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:2.5:maintenance_release6_patch2:*:*:*:*:*:* | ||
2.5CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:2.5:maintenance_release6_patch3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.