Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:MISC:CISCO-WEBEX-RCE

Severity

Minor

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Cisco WebEx Browser Extension Remote Code Execution

Release Date

2018/10/31

Update Number

3114

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Cisco WebEx Browser Extension Remote Code Execution


This signature detects attempts to exploit a known vulnerability against Cisco WebEx . A successful attack can lead to arbitrary code execution.

Extended Description

An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on Internet Explorer. A vulnerability in these Cisco WebEx browser extensions could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server and Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center) when they are running on Microsoft Windows. The vulnerability is a design defect in an application programing interface (API) response parser within the extension. An attacker that can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser.

Affected Products

  • Cisco activetouch_general_plugin_container 105
  • Cisco download_manager 2.1.0.9
  • Cisco gpccontainer_class 10031.6.2017.0125
  • Cisco webex 1.0.6
  • Cisco webex_meeting_center 2.6_base
  • Cisco webex_meeting_center 2.6_mr1
  • Cisco webex_meeting_center 2.6_mr2
  • Cisco webex_meeting_center 2.6_mr3
  • Cisco webex_meeting_center 2.7_base
  • Cisco webex_meeting_center 2.7_mr1
  • Cisco webex_meeting_center 2.7_mr2
  • Cisco webex_meeting_center t29_base
  • Cisco webex_meeting_center t30_base
  • Cisco webex_meeting_center t31_base
  • Cisco webex_meetings_server 2.0_base
  • Cisco webex_meetings_server 2.0_mr2
  • Cisco webex_meetings_server 2.0_mr3
  • Cisco webex_meetings_server 2.0_mr4
  • Cisco webex_meetings_server 2.0_mr5
  • Cisco webex_meetings_server 2.0_mr6
  • Cisco webex_meetings_server 2.0_mr7
  • Cisco webex_meetings_server 2.0_mr8
  • Cisco webex_meetings_server 2.0_mr9
  • Cisco webex_meetings_server 2.5_base
  • Cisco webex_meetings_server 2.5_mr1
  • Cisco webex_meetings_server 2.5_mr2
  • Cisco webex_meetings_server 2.5_mr3
  • Cisco webex_meetings_server 2.5_mr4
  • Cisco webex_meetings_server 2.5_mr5
  • Cisco webex_meetings_server 2.5_mr6
  • Cisco webex_meetings_server 2.6_base
  • Cisco webex_meetings_server 2.6_mr1
  • Cisco webex_meetings_server 2.6_mr2
  • Cisco webex_meetings_server 2.6_mr3
  • Cisco webex_meetings_server 2.7_base
  • Cisco webex_meetings_server 2.7_mr1
  • Cisco webex_meetings_server 2.7_mr2

References

  • BugTraq: 95737
  • CVE: CVE-2017-3823

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out