This application requires Javascript for optimal performance.

Cisco.WebEx.Player.ATAS32.DLL.Remote.Code.Execution

Release Date

Dec 22, 2011

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a Remote Code Execution vulnerability in Cisco WebEx Player.

The vulnerability is caused due to insufficient validation of some values in WebEx Recording Format (WRF) files. A remote attacker can exploit this by sending a specially crafted WRF file. Successful exploitation may allow the attacker to execute arbitrary code on the target host in the context of the application.

Affected Products

Cisco Systems WebEx Player Prior to T26 SP49 EP40
Cisco Systems WebEx Player Prior to T27 FR20
Cisco Systems WebEx Player Prior to T27 SP11 EP23
Cisco Systems WebEx Player Prior to T27 SP21 EP9
Cisco Systems WebEx Player Prior to T27 SP23
Cisco Systems WebEx Player Prior to T27 SP25 EP3
Cisco Systems WebEx Player Prior to T27 SP28

Recommended Actions

Apply patches or fixes, available from the website:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-webex

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-4004

Reference: VID-30567