CVE-2008-3558
Cisco WebEx Meeting Manager UCF - 'atucfobj.dll' ActiveX Remote Buffer Overflow
Severity Score
9.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long argument to the NewObject method.
Un desbordamiento de búfer en la región stack de la memoria en el control ActiveX de WebexUCFObject en la biblioteca atucfobj.dll en Cisco WebEx Meeting Managern anterior a versión 20.2008.2606.4919, permite a los atacantes remotos ejecutar código arbitrario por medio de un argumento largo en el método NewObject.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-08-08 CVE Reserved
- 2008-08-08 CVE Published
- 2010-09-20 First Exploit
- 2024-08-07 CVE Updated
- 2024-09-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/063692.html | Mailing List | |
http://www.kb.cert.org/vuls/id/661827 | Third Party Advisory | |
http://www.securityfocus.com/bid/30578 | Vdb Entry | |
http://www.securitytracker.com/id?1020641 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44250 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/6220 | 2024-08-07 | |
https://www.exploit-db.com/exploits/16604 | 2010-09-20 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/31397 | 2017-09-29 | |
http://www.cisco.com/en/US/products/products_security_advisory09186a00809e2006.shtml | 2017-09-29 | |
http://www.vupen.com/english/advisories/2008/2319 | 2017-09-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Webex Meeting Manager Search vendor "Cisco" for product "Webex Meeting Manager" | 20.2008.2601.4928 Search vendor "Cisco" for product "Webex Meeting Manager" and version "20.2008.2601.4928" | - |
Affected
|