ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Cisco plugs critical hole in WebEx, users urged to upgrade ASAP

criticalExploit / PoC exploited in the wildimportance 60CVE-2018-0112

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0112
A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server could allow an authenticated, remote attacker to ex

A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability is due to insufficient input validation by the Cisco WebEx clients. An attacker could exploit this vulnerability by providing meeting attendees with a malicious Flash (.swf) file via the file-sharing capabilities of the client. Exploitation of this vulnerability could allow arbitrary code execution on the system of a targeted user. This affects the clients installed by customers when accessing a WebEx meeting. The following client builds of Cisco WebEx Business Suite (WBS30, WBS31, and WBS32), Cisco WebEx Meetings, and Cisco WebEx Meetings Server are impacted: Cisco WebEx Business Suite (WBS31) client builds prior to T31.23.2, Cisco WebEx Business Suite (WBS32) client builds prior to T32.10, Cisco WebEx Meetings with client builds prior to T32.10, Cisco WebEx Meetings Server builds prior to 2.8 MR2. Cisco Bug IDs: CSCvg19384, CSCvi10746.

NVD description · AI analysis pending
9.03%
  • cisco webex meetings server
  • cisco webex meetings
  • cisco webex business suite 31
  • +1 more
Full article382 words · extracted from helpnetsecurity.com · click to collapse

Cisco has fixed a critical vulnerability in its Webex videoconferencing software that could be exploited to compromise meeting attendees’ systems by simply opening a booby-trapped Flash file shared in a meeting.

CVE-2018-0112

About the vulnerability (CVE-2018-0112)

The flaw is due to insufficient input validation by the Cisco Webex clients, and affects Cisco Webex Business Suite clients, Cisco Webex Meetings, and Cisco Webex Meetings Server.

(The Cisco Webex Business Suite (WBS) meeting services and Cisco Webex Meetings are a hosted multimedia conferencing solution that is managed and maintained by Cisco Webex. The Cisco Webex Meetings Server is a multimedia conferencing solution that customers can host in their private clouds. Customers download the Webex client application to attend meetings on the various Cisco Webex Centers.)

“To exploit this vulnerability, the client application would require a meeting attendee to open a malicious Flash file. An attacker may be able to accomplish this exploit by providing the malicious .swf file directly to users via the file-transfer capabilities of the client,” Cisco explained in an advisory published on Wednesday.

The good news is that it is not currently being exploited in the wild: it was discovered and reported to Cisco by Alexandros Zacharis, an officer in the European Union Agency for Network and Information Security (ENISA).

There are no workarounds for the flaw, so users should either upgrade their software to the latest releases or remove it from their systems altogether.

Other vulnerabilities fixed

Cisco has also released on Wednesday a number of security updates for several of its security appliances and other software.

Among the holes plugged is one affecting the company’s unified infrastructure management solution that simplifies data center operations.

“A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in the UCS Director end-user portal and perform any permitted operations on any virtual machine,” the company explained.

“The vulnerability is due to improper user authentication checks. An attacker could exploit this vulnerability by logging in to the UCS Director with a modified username and valid password. A successful exploit could allow the attacker to gain visibility into and perform actions against all virtual machines in the UCS Director end-user portal of the affected system.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/04/19/cisco-webex-cve-2018-0112/