WebEx ActiveX Multiple Remote Code Execution Vulnerabilities
BID:18860
CVE-2006-3423 |Info
WebEx ActiveX Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 18860 |
| Class: | Design Error |
| CVE: |
CVE-2006-3423 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2006 12:00AM |
| Updated: | Oct 04 2007 04:38PM |
| Credit: | David Dewey and Mark Dowd of ISS X-Force is credited with the discovery of this vulnerability. |
| Vulnerable: |
WebEx WebEx ActiveX Control 2.0.0.7 |
| Not Vulnerable: |
WebEx WebEx ActiveX Control 2.1 0 |
Discussion
WebEx ActiveX Multiple Remote Code Execution Vulnerabilities
WebEx ActiveX control is prone to multiple remote code-execution vulnerabilities.
An attacker could exploit these issues by creating a malicious web page that would initialize the WebEx ActiveX control, and then download and initialize malicious DLL files.
Exploiting this issue could allow an attacker to execute arbitrary code.
WebEx 2.0.0.7 and prior versions are affected.
WebEx ActiveX control is prone to multiple remote code-execution vulnerabilities.
An attacker could exploit these issues by creating a malicious web page that would initialize the WebEx ActiveX control, and then download and initialize malicious DLL files.
Exploiting this issue could allow an attacker to execute arbitrary code.
WebEx 2.0.0.7 and prior versions are affected.
Exploit / POC
WebEx ActiveX Multiple Remote Code Execution Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
WebEx ActiveX Multiple Remote Code Execution Vulnerabilities
Solution:
The vendor has released a fix to resolve this issue.
Solution:
The vendor has released a fix to resolve this issue.
References
WebEx ActiveX Multiple Remote Code Execution Vulnerabilities
References:
References:
- Vendor Homepage (WebEx)
- WebEx Advisory (WebEx)
- XForce Alert (Dewey and Mark Dowd - XForce)