Security News > 2020 > June > Cisco Adds New Security Features to Webex, Patches Serious Vulnerabilities

Cisco Adds New Security Features to Webex, Patches Serious Vulnerabilities
2020-06-18 13:57

Cisco announced this week that it has added new security features to Webex and that it has also patched several high-severity vulnerabilities in the conferencing product.

At its Cisco Live 2020 event, the networking giant informed customers that it has extended its data loss prevention retention, Legal Hold and eDiscovery features to Webex Meetings.

The company has also published several security advisories this week for Webex vulnerabilities, including three that have been classified as high severity and one rated medium severity.

The Webex Meetings Desktop App for Mac is affected by a vulnerability that allows a remote attacker, without authentication, to execute arbitrary code on the targeted system by abusing the application's software update feature and convincing the victim to access a malicious website that serves files similar to the ones hosted on a legitimate Webex website.

"In an attack scenario, any malicious local user or malicious process running on a computer where WebEx Client for Windows is installed can monitor the memory mapped file for a login token. Once found the token, like any leaked credentials, can be transmitted somewhere so that it can be used to login to the WebEx account in question, download Recordings, view/edit Meetings, etc," Trustwave said in a blog post.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/is9IQJxVDDg/cisco-adds-new-security-features-webex-patches-serious-vulnerabilities

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Cisco 2046 21 1771 1669 288 3749