follow

help me to improve quality

donate

Pages

Monday 17 July 2017

Critical RCE Vulnerability Found in Cisco WebEx Extensions, Again — Patch Now!






"I see several problems with the way sanitization works, and have produced a remote code execution exploit to demonstrate them," Ormandy said. "This extension has over 20M [million] active Chrome users alone, FireFox and other browsers are likely to be affected as well."
Cisco has already patched the vulnerability and released “Cisco WebEx Extension 1.0.12” update for Chrome and Firefox browsers that address this issue, though "there are no workarounds that address this vulnerability."

"This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center), and Cisco WebEx Meetings when they are running on Microsoft Windows," Cisco confirmed in an advisory released today.

Download Cisco WebEx Extension 1.0.12




In general, users are always recommended to run all software as a non-privileged user in an effort to diminish the effects of a successful attack.


1 comments: