cbcvebase.
CVE-2019-1939
published 2019-09-05

CVE-2019-1939: A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected…

PriorityP260high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.73%
90.8th percentile
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. This vulnerability is due to improper restrictions on software logging features used by the application on Windows operating systems. An attacker could exploit this vulnerability by convincing a targeted user to visit a website designed to submit malicious input to the affected application. A successful exploit could allow the attacker to cause the application to modify files and execute arbitrary commands on the system with the privileges of the targeted user.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscocisco_webex_teams>= unspecified < 3.0.12427.03.0.12427.0
ciscowebex_teams< 3.0.12427.03.0.12427.0
ciscowebex_teams_logging_feature

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a malicious website submitting crafted input to the Cisco Webex Teams Windows client via its logging feature — monitor for unexpected child processes or file modifications spawned by the Webex Teams process (e.g., CiscoCollabHost.exe or Teams.exe) following browser-to-app URI/protocol handler invocations.
  • Root cause is improper restrictions on software logging features on Windows — alert on anomalous log-related file writes or command execution originating from the Webex Teams client process on Windows endpoints.
  • ·No workarounds are available; patching to a fixed software version is the only mitigation. Track Cisco Bug ID CSCvp30119 for patch status.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.