Vulnerability record · CVE-2008-3558 · published 8 August 2008
CVE-2008-3558: Cisco WebEx Meeting Manager ActiveX control stack buffer overflow
Cisco · Webex Meeting Manager
The WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 has a stack-based buffer overflow. A long argument to the NewObject method overflows a stack buffer, letting a remote attacker run arbitrary code in the context of the browser or application hosting the control.
Description
Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long argument to the NewObject method.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows unauthenticated remote code execution with complete impact and has a public exploit plus very high EPSS, though it is not in KEV and requires user interaction.
What it is
The WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 has a stack-based buffer overflow. A long argument to the NewObject method overflows a stack buffer, letting a remote attacker run arbitrary code in the context of the browser or application hosting the control.
Impact
An attacker who triggers the overflow can execute arbitrary code with the privileges of the user running the affected control, typically leading to full system compromise. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
Reached over the network (AV:N) by delivering a crafted argument to the NewObject method of the ActiveX control, which requires the victim to load attacker-controlled content in a browser or application that instantiates the control. No authentication is needed (Au:N), but the medium attack complexity (AC:M) reflects the need to get the victim to load the malicious page or content.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but a public Exploit-DB entry (6220) exists and EPSS is high at 0.654 (99.2nd percentile), indicating meaningful real-world exploitation likelihood.
What to do
- Upgrade Cisco WebEx Meeting Manager to version 20.2008.2606.4919 or later, or apply the vendor advisory fix.
- Disable or remove the WebexUCFObject ActiveX control (atucfobj.dll) where WebEx Meeting Manager is not required.
- Set the ActiveX kill-bit for the affected control and restrict ActiveX execution in browsers.
- Block or tightly control access to untrusted web content and email links that could load the control.
- Retire or isolate end-of-life WebEx Meeting Manager installations that cannot be patched.
Detection
- Monitor for processes loading atucfobj.dll, especially from browser or Office processes, and alert on unexpected loads.
- Hunt for crash or exception events in browser/Office processes consistent with stack buffer overflow attempts.
- Review proxy and web logs for access to known exploit hosts or pages delivering the crafted NewObject argument.
- Check endpoint telemetry for child processes spawned by browsers or Office after loading the control.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-3558 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-3558), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.