Intrusion Prevention

Cisco.WebEx.Player.ATDL2006.DLL.Heap.Memory.Corruption

Description

This indicates an attack attempt against a Heap Memory Corruption vulnerability in Cisco WebEx Player.
The vulnerability is caused due to insufficient validation of some values in WebEx Recording Format (WRF) files. A remote attacker can exploit this by sending a specially crafted WRF file. Successful exploitation may allow the attacker to execute arbitrary code on the target host in the context of the application.

Affected Products

Cisco Systems WebEx Player Prior to T26 SP49 EP40
Cisco Systems WebEx Player Prior to T27 FR20
Cisco Systems WebEx Player Prior to T27 SP11 EP23
Cisco Systems WebEx Player Prior to T27 SP21 EP9
Cisco Systems WebEx Player Prior to T27 SP23
Cisco Systems WebEx Player Prior to T27 SP25 EP3
Cisco Systems WebEx Player Prior to T27 SP28

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply patches or fixes, available from the website:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-webex

CVE References

CVE-2011-3319