CVE Feed

    Dashboard / CVE / CVE-2017-3823

    CVE-2017-3823

    An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on Internet Explorer. A vulnerability in these Cisco WebEx browser extensions could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server and Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center) when they are running on Microsoft Windows. The vulnerability is a design defect in an application programing interface (API) response parser within the extension. An attacker that can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser.

    Published:Feb 1, 2017
    Last Modified:Apr 20, 2025
    EPS:Feb 1, 2017
    EPSS Score:0.79238
    CVSS Score:8.8

    Affected Products

    Vendor
    Cisco
    Product
    Activetouch General Plugin Container
    Vendor
    Cisco
    Product
    Download Manager
    Vendor
    Cisco
    Product
    Gpccontainer Class
    Vendor
    Cisco
    Product
    Webex
    Vendor
    Cisco
    Product
    Webex Meeting Center
    Vendor
    Cisco
    Product
    Webex Meetings Server

    Exploits

    No exploit reference

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High