Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
Cisco has not posed a security advisory about this, but this is not the first Active X vulnerability in WebEx.
In general, vulnerabilities in ActiveX -- beyond those just affecting Cisco products -- are gaining steam as a top attack vector due to the ease of exploitation, according to Umesh Wanve, research engineer at cloud Security as a Service (SaaS) vendor Zscaler. Over the past few years, there have been numerous buffer overflow and file overwrite vulnerabilities discovered in in ActiveX controls, many with working exploits, Wanve wrote on the Zscaler research blog. “These are very easy to exploit as there is a great deal of information available including vulnerability details, proof-of-concept exploits, etc. freely available on the Internet,” Wanve said.ActiveX controls have various properties and methods, which can be exploited if they're improperly coded, Wanve said.“If someone were to find a vulnerable property or method in an ActiveX control, it is not be difficult to create a working exploit and host it on a web server,” Wanve said. “If the vulnerable control is marked ‘safe for scripting' it can then be remotely called and exploited by a malicious web site.”In August 2008, a similar vulnerability was discovered in WebEx. Cisco's security advisory said a buffer overflow vulnerability was present in an ActiveX control used by the WebEx Meeting Manager. The flaw could have allowed an attacker to execute arbitrary code if a user browsed to a web-site that contained the malicious content. The vulnerability could have also been exploited through HTML embedded in e-mail messages or that is delivered via instant messaging applications. Last month, a free open-source tool to detect ActiveX vulnerabilities was released by the CERT Coordination Center at the Carnegie Mellon Software Engineering Institute in Pittsburgh. Dubbed Dranzer, the tool was tested on 22,000 ActiveX controls produced by more than 5,000 organizations. Dranzer is designed for use during the quality assurance phase of software creation and can help prevent flaws, such as buffer overflows, from being shipped in software to the public.See original article on scmagazineus.com
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.