ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

It's time to update your Cisco WebEx software again!

criticalExploit / PoC exploited in the wildimportance 60CVE-2018-0264CVE-2018-0253CVE-2018-0258

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0253
A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary com

A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. Commands executed by the attacker are processed at the targeted user's privilege level. The vulnerability is due to insufficient validation of the Action Message Format (AMF) protocol. An attacker could exploit this vulnerability by sending a crafted AMF message that contains malicious code to a targeted user. A successful exploit could allow the attacker to execute arbitrary commands on the ACS device. This vulnerability affects all releases of Cisco Secure ACS prior to Release 5.8 Patch 7. Cisco Bug IDs: CSCve69037.

NVD description · AI analysis pending
9.87%
  • cisco secure access control system
CVE-2018-0258
A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any director

A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects the following products: Cisco Prime Data Center Network Manager (DCNM) Version 10.0 and later, and Cisco Prime Infrastructure (PI) All versions. Cisco Bug IDs: CSCvf32411, CSCvf81727.

NVD description · AI analysis pending
9.848%
  • cisco prime data center network manager
  • cisco prime infrastructure
CVE-2018-0264
A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute

A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. An attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and persuading the user to follow the link or open the file. Successful exploitation could allow the attacker to execute arbitrary code on the user's system. This vulnerability affects Cisco WebEx Business Suite meeting sites, Cisco WebEx Meetings sites, Cisco WebEx Meetings Server, and Cisco WebEx ARF players. The following client builds of Cisco WebEx Business Suite (WBS31 and WBS32), Cisco WebEx Meetings, and Cisco WebEx Meetings Server are affected: Cisco WebEx Business Suite (WBS31) client builds prior to T31.23.4, Cisco WebEx Business Suite (WBS32) client builds prior to T32.12, Cisco WebEx Meetings with client builds prior to T32.12, Cisco WebEx Meeting Server builds prior to 3.0 Patch 1. Cisco Bug IDs: CSCvh85410, CSCvh85430, CSCvh85440, CSCvh85442, CSCvh85453, CSCvh85457.

NVD description · AI analysis pending
9.63%
  • cisco webex business suite 31
  • cisco webex business suite 32
  • cisco webex meeting server
  • +1 more
Full article474 words · extracted from helpnetsecurity.com · click to collapse

Cisco has released security updates for a variety of its offerings, including some that fix critical remote code execution vulnerabilities in Webex software, Cisco Secure ACS (its policy-driven access control system), and a servlet included in two of its products.

Cisco Webex security updates

Webex flaw (CVE-2018-0264)

If you use Cisco’s WebEx videoconferencing software and you haven’t implemented the security update released last month, you should definitely get patching right now as your computer can be compromised by simply opening a recording of a past online meeting.

The vulnerability is present in Cisco Webex Network Recording Player for Advanced Recording Format (ARF) files, and can be exploited by unauthenticated, remote attackers: they only need to booby-trap an ARF file, send it or a link to it to a user, and wait for it to be opened.

The ARF file format is used to store Webex meeting recordings that have been recorded on a Webex meeting site or on the computer of an online meeting attendee.

The Cisco Webex ARF Player is used to play back and edit Webex ARF recording files. The application can be installed automatically when a user accesses a recording file that is hosted on a Cisco Webex Meetings site (for streaming playback mode) or manually after downloading the application (for offline playback of recording files).

There is no workaround for the flaw – if you don’t want to risk getting hit with an exploit, either install the offered security update for Webex Business Suite, Webex Meetings, and Webex Meeting Server or remove the software from your system.

The vulnerability was discovered by Kushal Arvind Shah of Fortinet’s FortiGuard Labs and there is no indication that it is currently being exploited in the wild.

The updates for the Webex software also include a fix for a less critical RCE unearthed by the same researcher.

The other two critical RCE vulnerabilities

The first one (CVE-2018-0253), affecting all releases of Cisco Secure ACS prior to Release 5.8 Patch 7, could be triggered by the target opening a specially crafted Action Message Format (AMF) message that contains malicious code, allowing the attacker to execute arbitrary commands on the ACS device.

The second one (CVE-2018-0258) affects the Cisco Prime File Upload servlet included in Cisco Prime Data Center Network Manager (DCNM), version 10.0 and later, and all versions of Cisco Prime Infrastructure (PI).

“An attacker could exploit this vulnerability by uploading a crafted Java Server Pages (JSP) file to a specific folder using path traversal techniques and then executing that file remotely. An exploit could allow the attacker to execute arbitrary commands on the affected device with the privileges of the SYSTEM user,” Cisco noted.

Both vulnerabilities have been reported to Cisco by security researchers and the Cisco Product Security Incident Response Team is not aware of any public announcements or malicious use of them.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/05/03/cisco-webex-security-updates/