Researchers Tavis Ormandy and Cris Neckar privately disclosed a critical vulnerability in Cisco s WebEx extension for Chrome and Firefox that allows for remote code execution. Tens of millions of computers have the extension installed. The bug could be exploited by an attacker hosting crafted code online, and enticing users to visit the site. The vulnerability also affects browser extensions for Cisco WebEx Meetings Server, WebEx Centers (Meeting, Event, Training and Support centers) and Cisco Webex Meetings on Windows machines.
Source: https://threatpost.com/cisco-patches-another-critical-ormandy-bug-in-webex-extension/126879/