CVE-2025-20236
published 2025-04-16CVE-2025-20236: A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files…
PriorityP258high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.94%
56.8th percentile
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user.
This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | webex_app | — | — |
| cisco | webex_teams | — | — |
| cisco | webex_teams | — | — |
| cisco | webex_teams | — | — |
| cisco | webex_teams | — | — |
| cisco | webex_teams | — | — |
| cisco | webex_teams | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is a crafted meeting invite link (custom URL scheme) that triggers arbitrary file download and command execution — monitor for anomalous Webex custom URL handler invocations or unexpected child processes spawned by the Webex App process. ↗
- →Vulnerability is in the custom URL parser of Cisco Webex App — focus detection on processing of meeting invite links (webexteams:// or similar custom URI schemes) with unexpected or malformed parameters that could carry file download payloads. ↗
- →No workarounds exist; patch is the only mitigation — flag any unpatched Webex App 44.6/44.7 host as high-priority for remediation and consider blocking custom Webex URI handler registration until patched. ↗
- →Vulnerability impacts Cisco Webex App regardless of operating system or system configuration — ensure detection and patching coverage spans Windows, macOS, and Linux endpoints. ↗
- ·Cisco internal bug tracker reference for this vulnerability is CSCwn07296 — useful for cross-referencing vendor patch notes and TAC cases. ↗
- ·The vulnerability is classified under CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) — detection logic should account for file inclusion/download triggered by URL parsing, not a memory corruption primitive. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Webex App Client-Side Remote Code Execution Vulnerability
vendor_cisco·2025-04-16·CVSS 8.8
CVE-2025-20236 [HIGH] CWE-829 Cisco Webex App Client-Side Remote Code Execution Vulnerability
Cisco Webex App Client-Side Remote Code Execution Vulnerability
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user.
This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vuln
Cisco
Cisco Webex App Client-Side Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20236 Cisco Webex App Client-Side Remote Code Execution Vulnerability
CVE-2025-20236: Cisco Webex App Client-Side Remote Code Execution Vulnerability
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-82
GHSA
GHSA-rv87-h47c-m27v: A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary f
ghsa_unreviewed·2025-04-16
CVE-2025-20236 [HIGH] CWE-829 GHSA-rv87-h47c-m27v: A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary f
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user.
This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.
No detection rules found.
No public exploits indexed.
2025-04-16
Published