CVE-2017-3823

high
Published 2017-02-01 ยท Modified 2026-05-13
CVSS v3
8.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.8

Description

An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on Internet Explorer. A vulnerability in these Cisco WebEx browser extensions could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server and Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center) when they are running on Microsoft Windows. The vulnerability is a design defect in an application programing interface (API) response parser within the extension. An attacker that can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser.

Predictions

Exploit likelihood
92%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Metasploit modules

Cisco WebEx Chrome Extension RCE (CVE-2017-3823)
Source code queued for fetch โ€” refresh in a moment.

Application impact

VendorProductVersionsFixed
cisco ciscoactivetouch_general_plugin_container105
cisco ciscodownload_manager2.1.0.9
cisco ciscogpccontainer_class{"endIncluding":"10031.6.2017.0125"}
cisco ciscowebex{"endIncluding":"1.0.6"}
cisco ciscowebex_meetings_server2.0_base
cisco ciscowebex_meetings_server2.0_mr2
cisco ciscowebex_meetings_server2.0_mr3
cisco ciscowebex_meetings_server2.0_mr4
cisco ciscowebex_meetings_server2.0_mr5
cisco ciscowebex_meetings_server2.0_mr6
cisco ciscowebex_meetings_server2.0_mr7
cisco ciscowebex_meetings_server2.0_mr8
cisco ciscowebex_meetings_server2.0_mr9
cisco ciscowebex_meetings_server2.5_base
cisco ciscowebex_meetings_server2.5_mr1
cisco ciscowebex_meetings_server2.5_mr2
cisco ciscowebex_meetings_server2.5_mr3
cisco ciscowebex_meetings_server2.5_mr4
cisco ciscowebex_meetings_server2.5_mr5
cisco ciscowebex_meetings_server2.5_mr6
cisco ciscowebex_meetings_server2.6_base
cisco ciscowebex_meetings_server2.6_mr1
cisco ciscowebex_meetings_server2.6_mr2
cisco ciscowebex_meetings_server2.6_mr3
cisco ciscowebex_meetings_server2.7_base
cisco ciscowebex_meetings_server2.7_mr1
cisco ciscowebex_meetings_server2.7_mr2
cisco ciscowebex_meeting_center2.6_base
cisco ciscowebex_meeting_center2.6_mr1
cisco ciscowebex_meeting_center2.6_mr2
cisco ciscowebex_meeting_center2.6_mr3
cisco ciscowebex_meeting_center2.7_base
cisco ciscowebex_meeting_center2.7_mr1
cisco ciscowebex_meeting_center2.7_mr2
cisco ciscowebex_meeting_centert29_base
cisco ciscowebex_meeting_centert30_base
cisco ciscowebex_meeting_centert31_base

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.