Home > Financial Services Information Security News > WebEx addresses ActiveX flaw
Financial Services Information Security News:
EMAIL THIS

WebEx addresses ActiveX flaw

By Dennis Fisher, News Director
06 Jul 2006 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Researchers at Internet Security Systems Inc. on Thursday said they had discovered a serious flaw in the widely used WebEx Web conferencing software. But WebEx already has taken steps to prevent attacks.

According to the ISS X-Force, the vulnerability involves the way that the software downloads certain components when users install the WebEx package on their machines.

WebEx Communications Inc. is the Web conferencing market leader and the software is used in thousands of enterprises and organizations around the world.

When users participate in a Web-based meeting using the WebEx software, they must first download a small client. WebEx employs an ActiveX control to download the client onto users' PCs.

The specific problem occurs during the download process when the ActiveX control fails to verify the source or content of the components it installs. This could enable an attacker to create a malicious Web page and trick users into downloading malware instead of the WebEx software, ISS said in its advisory.

The results of a successful attack could vary, but an attacker who is able to implant software on a user's machine could easily gain access to sensitive data or use the PC to attack other assets on the same network.

ISS notified WebEx of the problem some time ago and the two companies developed a fix that WebEx already has implemented. The WebEx service will automatically update the ActiveX control on the machines of all users who access the service going forward.

Tags: Enterprise email security and messaging securityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Enterprise email security and messaging security
Too many encryption methods make secure communications difficult
Shifting to a flexible information security framework
Google ordered to deactivate Gmail account after bank email error
Wyoming bank sues Google after bank employee email mishap
Wells Fargo deploys Voltage for secure email
Study of banking malware analyzes underground economy
Cisco: Cybercriminals more savvy than ever in 2008
Secure communications
How to easily integrate managed email security services
Email security and compliance best practices, part two

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Financial Security News Topics: Compliance, Management Strategy, Security Technology
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts