Cisco.WebEx.nativeMessaging.Command.Execution

description-logoDescription

This indicates an attack attempt to exploit a command execution vulnerability in Cisco WebEx Chrome Extension.
The vulnerability is caused by lacking of checking the message sent by "cwcsf-nativemsg-iframe-43c85c0d-d633-af5e-c056-32dc7efc570b.html". A remote attacker may be able to exploit this to execute arbitrary code within the context of the application.

affected-products-logoAffected Products

Cisco WebEx Extension for Chrome before version 1.0.3

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Update the extension to the latest version.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-06-10 14.629 Severity:critical:high