CVE-2019-1939

HIGH

Cisco Webex Teams < 3.0.12427.0 - Unauthenticated Remote Code Execution via Software Logging Feature

Title source: llm
STIX 2.1

Description

A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. This vulnerability is due to improper restrictions on software logging features used by the application on Windows operating systems. An attacker could exploit this vulnerability by convincing a targeted user to visit a website designed to submit malicious input to the affected application. A successful exploit could allow the attacker to cause the application to modify files and execute arbitrary commands on the system with the privileges of the targeted user.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0473
EPSS Percentile 90.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269 CWE-74
Status published
Products (1)
cisco/webex_teams < 3.0.12427.0
Published Sep 05, 2019
Tracked Since Feb 18, 2026