vendor:
Webex Player
by:
Francis Provencher of COSIG
5,5
CVSS
MEDIUM
Out-of-bound Memory Corruption
119
CWE
Product Name: Webex Player
Affected Version From: T29.10
Affected Version To: T29.10
Patch Exists: Yes
Related CWE: CVE-2016-1415
CPE: a:cisco:webex_player
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2016
Cisco Webex Player Vulnerability
The flaw exists within the parsing process of an invalid ARF file. An attacker can use this flaw to create an out-of-bound memory corruption which could allow for the execution of arbitrary code in the context of the current user.
Mitigation:
Cisco has released a patch to address this vulnerability.