CVE-2017-6753

high
Published 2017-07-25 · Modified 2026-05-13
CVSS v3
8.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
VIR risk
8.8

Description

A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center), and Cisco WebEx Meetings when they are running on Microsoft Windows. The vulnerability is due to a design defect in the extension. An attacker who can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser. The following versions of the Cisco WebEx browser extensions are affected: Versions prior to 1.0.12 of the Cisco WebEx extension on Google Chrome, Versions prior to 1.0.12 of the Cisco WebEx extension on Mozilla Firefox. Cisco Bug IDs: CSCvf15012 CSCvf15020 CSCvf15030 CSCvf15033 CSCvf15036 CSCvf15037.

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
cisco ciscowebex_event_centert30_base
cisco ciscowebex_event_centert31_base
cisco ciscowebex_event_centert32_base
cisco ciscowebex_meeting_centert30_base
cisco ciscowebex_meeting_centert31_base
cisco ciscowebex_meeting_centert32_base
cisco ciscowebex_meetingst30_base
cisco ciscowebex_meetings_server1.1_base
cisco ciscowebex_meetings_server1.5.1.6
cisco ciscowebex_meetings_server1.5.1.131
cisco ciscowebex_meetings_server1.5_base
cisco ciscowebex_meetings_server2.0.1.107
cisco ciscowebex_meetings_server2.0_base
cisco ciscowebex_meetings_server2.5.1.5
cisco ciscowebex_meetings_server2.5.1.29
cisco ciscowebex_meetings_server2.5.99.2
cisco ciscowebex_meetings_server2.5_base
cisco ciscowebex_meetings_server2.6.0
cisco ciscowebex_meetings_server2.6.1.39
cisco ciscowebex_meetings_server2.7.1
cisco ciscowebex_meetings_server2.7_base
cisco ciscowebex_meetings_server2.8_base
cisco ciscowebex_meetings_server_2.0mr2
cisco ciscowebex_meetings_server_2.0mr3
cisco ciscowebex_meetings_server_2.0mr4
cisco ciscowebex_meetings_server_2.0mr5
cisco ciscowebex_meetings_server_2.0mr6
cisco ciscowebex_meetings_server_2.0mr7
cisco ciscowebex_meetings_server_2.0mr8
cisco ciscowebex_meetings_server_2.0mr9
cisco ciscowebex_meetings_server_2.0_mr8_patch1
cisco ciscowebex_meetings_server_2.0_mr9_patch1
cisco ciscowebex_meetings_server_2.0_mr9_patch2
cisco ciscowebex_meetings_server_2.0_mr9_patch3
cisco ciscowebex_meetings_server_2.5mr1
cisco ciscowebex_meetings_server_2.5mr2
cisco ciscowebex_meetings_server_2.5mr3
cisco ciscowebex_meetings_server_2.5mr4
cisco ciscowebex_meetings_server_2.5mr5
cisco ciscowebex_meetings_server_2.5mr6
cisco ciscowebex_meetings_server_2.5_mr2_patch1
cisco ciscowebex_meetings_server_2.5_mr5_patch1
cisco ciscowebex_meetings_server_2.5_mr6_patch1
cisco ciscowebex_meetings_server_2.5_mr6_patch2
cisco ciscowebex_meetings_server_2.5_mr6_patch3
cisco ciscowebex_meetings_server_2.5_mr6_patch4
cisco ciscowebex_meetings_server_2.6mr1
cisco ciscowebex_meetings_server_2.6mr2
cisco ciscowebex_meetings_server_2.6mr3
cisco ciscowebex_meetings_server_2.6_mr1_patch1
cisco ciscowebex_meetings_server_2.6_mr2_patch1
cisco ciscowebex_meetings_server_2.6_mr3_patch1
cisco ciscowebex_meetings_server_2.6_mr3_patch2
cisco ciscowebex_meetings_server_2.7mr1
cisco ciscowebex_meetings_server_2.7mr2
cisco ciscowebex_meetings_server_2.7_mr1_patch1
cisco ciscowebex_meetings_server_2.7_mr2_patch1
cisco ciscowebex_support_centert30_base
cisco ciscowebex_support_centert31_base
cisco ciscowebex_support_centert32_base
cisco ciscowebex_training_centert30_base
cisco ciscowebex_training_centert31_base
cisco ciscowebex_training_centert32_base

References

CWEs

CWE-119

💬 Discuss CVE-2017-6753 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.