Vulnerability would have allowed an attacker to gain access to sensitive information on a system, Trustwave’s SpiderLab says.
Cisco has patched a security flaw in its Webex for Windows videoconferencing and messaging software that would have allowed an authenticated attacker to impersonate a legitimate user, download recordings, view or edit meeting information, and steal usernames and other data.
The vulnerability — tracked as CVE-2020-3347 — resulted from what Cisco described as the unsafe use of shared memory in versions of Webex Meetings Desktop App for Windows earlier than 40.6.0. It’s one of three flaws in Webex for which the company issued patches this week. […]