CVE-2018-0387: Input Validation
A vulnerability in Cisco Webex Teams (for Windows and macOS) could allow an unauthenticated, remote attacker to execute arbitrary code on the user's device, possibly with elevated privileges. The vulnerability occurs because Cisco Webex Teams does not properly sanitize input. An attacker could exploit the vulnerability by sending a user a malicious link and persuading the user to follow the link. A successful exploit could allow the attacker to execute arbitrary code on the user's system. Cisco Bug IDs: CSCvh66250.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0387?
CVE-2018-0387 has been assigned a high severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2018-0387?
To fix CVE-2018-0387, update your Cisco Webex Teams software to the latest version available.
What are the affected platforms for CVE-2018-0387?
CVE-2018-0387 affects Cisco Webex Teams running on Windows and macOS.
Can CVE-2018-0387 be exploited remotely?
Yes, CVE-2018-0387 can be exploited by an unauthenticated remote attacker.
What type of attacks are possible using CVE-2018-0387?
CVE-2018-0387 can allow attackers to execute arbitrary code, possibly with elevated privileges.