Security News Unusual Remote Execution Bug in Cisco WebEx Discovered by Researchers

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
While remote code execution vulnerabilities are pretty common, a new one discovered in Cisco's WebEx online and video collaboration software is definitely different. That is because users can remotely execute commands through a component of the WebEx client even when WebEx does not listen for remote connections.

Remote code execution vulnerabilities are bugs that allow a users to remotely connect to a vulnerable application and cause commands to be executed on the remote computer. These are critical bugs because they commonly allow commands to run with elevated privileges.

This new remote code execution vulnerability was disclosed yesterday by Ron Bowes and Jeff McJunkin of the hack challenge organization Counter Hack while performing a recent pentest. Their initial goal was to elevate the permissions of a local standard user account, but they instead found a very interesting remote code execution bug that they have titled "WebExec".
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top