Several critical vulnerabilities that were identified in Cisco WebEX products are being fixed with some updates from the company.
Cisco WebEx is a subsidiary company that provides products and support for video conferencing applications, mainly over the Internet. Its systems are quite secure and well-designed, which makes its customers more productive .
The vulnerabilities allowed a hacker to send infected .ARF and .WRF files via email or URL. If the attack was successful, we had DDoS issues in the application and sometimes even an arbitrary code execution vulnerability. Let's see which products and versions are affected:
- Cisco WebEx ARF Player
- Cisco WebEx WRF Player
- Cisco WebEx Business Suite WBS30 (up to 20)
- Cisco WebEx Business Suite WBS31 (up to 14.1)
- Cisco WebEx Business Suite WBS32 (up to 2)
- Cisco WebEx Meetings (up to 14)
- Cisco WebEx Meetings Server (up to 7MR3)
Regarding the Cisco WebEx meeting site, one can check if they are using a vulnerable version by logging in and going to Support>Downloads. Then, under the “About Meeting Center” option, the version (build) you have will be displayed.
For the Cisco WebEx meeting client, you should click Help>About Cisco WebEx Meeting Center where the version (build) you have is displayed. For those operating in a MacOS environment, you will find it in the Meeting Center tab > About Cisco WebEx Meeting Center.
The CVEs being fixed are: CVE-2017-12367, CVE-2017-12368, CVE-2017-12369, CVE-2017-12370, CVE-2017-12371, CVE-2017-12372
Attention: Those of you who have installed these applications and do not have automatic updates active will need to download the new versions of the programs manually.

