CVE-2019-15283 describes multiple arbitrary code execution vulnerabilities in Cisco Webex Network Recording Player and Webex Player for Microsoft Windows. These flaws stem from insufficient validation of ARF/WRF recording files, impacting various Cisco Webex Meetings products. With a CVSS score of 7.8 (HIGH), successful exploitation requires user interaction (opening a malicious file) and can lead to arbitrary code execution with the user's privileges. While not actively exploited in the wild and lacking public exploit code, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 39.5.0, < 39.5.12CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings:*:*:*:*:*:*:*:* | ||
< 1.3.44CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:*:*:*:*:*:*:*:* | ||
32.11CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:32.11:*:*:*:*:*:*:* | ||
39.4.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:39.4.0:*:*:*:*:*:*:* | ||
t32.9CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:t32.9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.