Cisco Patches WebEx Bugs

  /     /     /  
Publicated : 22/11/2024   Category : security


Cisco Patches WebEx Bugs


Attacks could exploit stack overflows in WebEx Player and WebEx Media Center to compromise or crash computers.



Slideshow: Cisco Umi Takes Telepresence To The Home

(click image for larger view and for slideshow)
On Monday, Cisco updated its WebEx software to patch two bugs that attackers could exploit to crash or compromise a users system.
The vulnerabilities were first identified by Core Security in October 2010. It then delayed releasing a
security advisory
until Cisco had time to create an emergency patch and fully distribute updates for WebEx Meeting Center, which runs in a software-as-a-service (SaaS) environment.
According to Core Security, the vulnerabilities in previous versions of WebEx Player and WebEx Meeting Center would allow an attacker to create a buffer overflow and take control of a users machine. The buffer overflows can be triggered if users run a malicious WebEx recording file (.wrf) or Web poll questionnaire (.atp).
Numerous types of attacks are possible for exploiting the vulnerabilities. For example, publishing a malicious WebEx recording file in a WebEx meeting can compromise all meeting participants PCs. Meanwhile, a malicious .atp file served during a meeting could disconnect the host, causing the clients to cycle the malicious file amongst themselves, while the file went about exploiting their systems.
These files trigger a reliably exploitable stack-based buffer overflow, said Core Security. Reliable code execution is possible because a big chunk of the stack is overwritten.
Core Security said it discovered the WebEx recording file vulnerability by fuzzing -- or altering -- a .wrf file to see what would result, which involved modifying only one byte. A portion of the new files execution pointed to a user call instruction and allowed a hacker to execute other functions on the machine, said Core Security. Such files, which use a closed and undocumented file format, are used to play back WebEx session recordings.
To address the WebEx Player vulnerability, Core Security recommends uninstalling any previous versions of the application and installing the
latest version
. Meanwhile, the WebEx Meeting Center vulnerability has been remediated by Cisco using a server-side fix.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Cisco Patches WebEx Bugs