Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: SANS Internet Storm Center SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Cisco WebEx WRF Player Vulnerabilities

Cisco today released details of a set of buffer overflow vulnerabilities and fixes for their WebEx WRF player.  The exploits describe multiple buffer overflows caused by a maliciously crafted WRF file (generally posted on a website), or by attending a WebEx meeting with an attacker attending.  The results of the exploit can result in execution of arbitrary code on the target system. 

The exploits are categorized as: CVE-2009-2875, CVE-2009-2876, CVE-2009-2877, CVE-2009-2878, CVE-2009-2879 and CVE-2009-2880.

The WebEx site itself has the fixed client code.  If you have an inhouse WebEx server, updating the server updates all the clients (as they connect).  You won't find an easier to install fix than this one!

From the Cisco advisory, the "first fixed" releases are listed below, by Major Release and Client OS.  All versions subsequent to these are fixed as well.


Major Release 26.x

Major Release 27.x

Microsoft Windows

26.49.32; available now except lockdown sites

27.10.x; available now for non-PSO and non-lockdown sites

Mac OS X

26.49.35; available early February 2010

27.11.8; available now for non-PSO and non-lockdown sites


26.49.35; available early February 2010

27.11.8; available now for non-PSO and non-lockdown sites


The full cisco advisory is here ==>


Rob VandenBrink

572 Posts
ISC Handler
Dec 16th 2009
I met a question when using u Cisco's webex recorder. The output is WRF which I have never seen before. However when I tried converting it to mp4 it require a password which is not my account, sucks! And I turn to a guide on the internet that says I first need to convert wrf to WMV, however, i followed it, after conversion, the video is black screen! What are you guys doing in this program? Kidding me?

Sign Up for Free or Log In to start participating in the conversation!