CVE-2016-1464: Input Validation
Published Sep 3, 2016
·Updated
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug ID CSCva09375.
Affected Software
1 affected component
Cisco Webex Wrf Player T29=sp10_base
Event History
Sep 3, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1464?
CVE-2016-1464 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2016-1464?
To mitigate CVE-2016-1464, ensure that you are using an updated version of the Cisco WebEx Meetings Player that does not support WRF file playback.
3
What types of attacks can be executed through CVE-2016-1464?
CVE-2016-1464 allows attackers to execute arbitrary code on affected systems via crafted WRF files.
4
Which software versions are affected by CVE-2016-1464?
CVE-2016-1464 affects Cisco WebEx Meetings Player T29.10, specifically the sp10_base version.
5
Is user interaction required for CVE-2016-1464 exploitation?
Yes, exploitation of CVE-2016-1464 requires the victim to open a malicious WRF file.