Description
This module exploits a stack-based buffer overflow in WebEx's WebexUCFObject ActiveX Control. If a long string is passed to the 'NewObject' method, a stack- based buffer overflow will occur when copying attacker-supplied data using the sprintf function.
It is noteworthy that this vulnerability was discovered and reported by multiple independent researchers. To quote iDefense's advisory, "Before this issue was publicly reported, at least three independent security researchers had knowledge of this issue; thus, it is reasonable to believe that even more people were aware of this issue before disclosure."
NOTE: Due to input restrictions, this exploit uses a heap-spray to get the payload into memory unmodified.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/browser/webex_ucf_newobjectmsf undefined(webex_ucf_newobject) > show actions ...actions...msf undefined(webex_ucf_newobject) > set ACTION < action-name >msf undefined(webex_ucf_newobject) > show options ...show and set options...msf undefined(webex_ucf_newobject) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub