CISCO-SA-20180418-WBS
A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability is due to insufficient input validation by the Cisco WebEx clients. An attacker could exploit this vulnerability by providing meeting attendees with a malicious Flash (.swf) file via the file-sharing capabilities of the client. Exploitation of this vulnerability could allow arbitrary code execution on the system of a targeted user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-wbs ["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-wbs"]
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco Webex Meetings | ||
| Cisco WebEx Training Center | ||
| Cisco WebEx Meeting Center | ||
| Cisco WebEx Meetings Server | ||
| Cisco WebEx Support Center | ||
| Cisco WebEx Event Center |
Timeline
- Apr 18, 2018 CVE Published
- May 2, 2018 CVE Updated
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-wbs advisory
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html url
- https://collaborationhelp.cisco.com/article/en-us/WBX000026396 url
- https://collaborationhelp.cisco.com/article/en-us/WBX28548 url
- https://www.cisco.com/c/en/us/products/end-user-license-agreement.html url
- https://www.cisco.com/go/psirt url
- https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html url
- https://software.cisco.com fix