Cisco WebEx Browser Extension Remote Code Execution Vulnerability
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Cisco Webex Meetings Online
Cisco WebEx Extension 1.0.6 and earlier on Google ChromeActiveTouch General Plugin Container 105 on Mozilla Firefox
GpcContainer Class ActiveX versions prior to 10031.6.2017.0127 on Internet Explorer
Threat details
The vulnerability is due to a defect in an application programming interface (API) response parser within the plugin. An attacker that is able to convince an affected user to visit an attacker-controlled web-page with an affected browser can exploit the vulnerability. Successful exploitation can lead to arbitrary code execution with the privileges of the affected browser.
Cisco has released patches for Google Chrome, Mozilla Firefox and Internet Explorer to address this vulnerability.
A system that has been patched is still vulnerable to a Cross Site Script (XSS) attack through the https://*.webex.com domain whitelist.
For further information please see:
CVE Vulnerabilities
Last edited: 17 February 2020 11:29 am