First published: Wed Jun 02 2021(Updated: )
A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the multimedia viewer feature. An attacker could exploit this vulnerability by sharing a file through the multimedia viewer feature. A successful exploit could allow the attacker to bypass security protections and prevent warning dialogs from appearing before files are offered to other users. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-multimedia-26DpqVRO
Credit: Alexandros Zacharis ENISA
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Client | ||
Cisco Webex Meetings Server Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-webex-multimedia-26DpqVRO is high due to the potential for authenticated remote attackers to bypass security protections.
To fix cisco-sa-webex-multimedia-26DpqVRO, apply the latest updates and patches provided by Cisco for Webex Meetings and Webex Meetings Server.
Users of Cisco Webex Meetings and Cisco Webex Meetings Server are affected by cisco-sa-webex-multimedia-26DpqVRO.
cisco-sa-webex-multimedia-26DpqVRO is caused by unsafe handling of shared content within the multimedia viewer feature of Webex.
Attackers could exploit the cisco-sa-webex-multimedia-26DpqVRO vulnerability to bypass security protections in the application.