Skip to main content

Cisco WebEx Browser Extension Remote Code Execution Vulnerability

A vulnerability identified in Cisco’s WebEx browser extension allows an unauthenticated, remote attacker to execute arbitrary code on the affected browser on an affected system.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability identified in Cisco’s WebEx browser extension allows an unauthenticated, remote attacker to execute arbitrary code on the affected browser on an affected system.

Affected platforms

The following platforms are known to be affected:

Cisco Webex Meetings Online

Cisco WebEx Extension 1.0.6 and earlier on Google Chrome
ActiveTouch General Plugin Container 105 on Mozilla Firefox
GpcContainer Class ActiveX versions prior to 10031.6.2017.0127 on Internet Explorer

Threat details

The vulnerability is due to a defect in an application programming interface (API) response parser within the plugin. An attacker that is able to convince an affected user to visit an attacker-controlled web-page with an affected browser can exploit the vulnerability. Successful exploitation can lead to arbitrary code execution with the privileges of the affected browser.

Cisco has released patches for Google Chrome, Mozilla Firefox and Internet Explorer to address this vulnerability.

A system that has been patched is still vulnerable to a Cross Site Script (XSS) attack through the https://*.webex.com domain whitelist.

For further information please see:

CVE-2017-3823


Remediation steps

Type Step
  • Ensure patches are applied in a timely manner


CVE Vulnerabilities

Last edited: 17 February 2020 11:29 am