← Vulnerability feed

Vulnerability record · CVE-2019-1636 · published 23 January 2019

CVE-2019-1636: Cisco Webex Teams Windows client unsafe search path allows command execution

Cisco · Webex Teams

The Cisco Webex Teams (formerly Spark) Windows client uses unsafe search paths for its application URI, so it can load libraries from a directory controlled via a crafted link. An attacker who convinces a user to follow a malicious link and can place a crafted library in a reachable directory may get code to run. It matters because the client runs with the user's privileges and the flaw is trivially triggered by a link.

7.8 CVSS 3.0 High EPSS 47% · top 1.2% CWE-78 · OS command injection
7.8CVSS 3.0 base score, v2 9.3
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows operating systems. An attacker could exploit this vulnerability by convincing a targeted user to follow a malicious link. Successful exploitation could cause the application to load libraries from the directory targeted by the URI link. The attacker could use this behavior to execute arbitrary commands on the system with the privileges of the targeted user if the attacker can place a crafted library in a directory that is accessible to the vulnerable system.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 7.8 with high confidentiality, integrity and availability impact and a very high EPSS score, though exploitation requires user interaction and local library placement.

What it is

The Cisco Webex Teams (formerly Spark) Windows client uses unsafe search paths for its application URI, so it can load libraries from a directory controlled via a crafted link. An attacker who convinces a user to follow a malicious link and can place a crafted library in a reachable directory may get code to run. It matters because the client runs with the user's privileges and the flaw is trivially triggered by a link.

Impact

An attacker can execute arbitrary commands on the targeted system with the privileges of the targeted user, giving code execution in that user's context.

Attack surface

Reached locally through the Windows application URI handler; the CVSS vector is AV:L with UI:R and PR:N, so no authentication is needed but the victim must follow a malicious link and a crafted library must be placed in a directory accessible to the system.

Exploitation

Not listed in CISA KEV and no ransomware use is documented; EPSS is high (0.46891, 98.8th percentile), and references are only vendor and third-party advisories with no public exploit tag.

What to do

  • Apply the Cisco advisory fix for the Webex Teams client (cisco-sa-20190123-webex-teams) and update to a corrected release.
  • Restrict write access to directories the client searches so untrusted users cannot plant libraries.
  • Warn users not to follow unsolicited Webex Teams or Spark URI links.
  • Where feasible, limit or disable the Webex Teams URI handler until patched.

Detection

  • Monitor for unexpected DLL or library loads by the Webex Teams client from user-writable or unusual directories.
  • Alert on Webex Teams/Spark URI handler launches originating from email, chat or web links.
  • Audit file creation of libraries in directories reachable by the client for suspicious names or unsigned binaries.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-1636 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-20236Cisco webex teams inclusion from untrusted sphere vulnerabilityA vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary …EPSS 0.97%8.8CVE-2019-1939Cisco webex teams injection vulnerabilityA vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affec…EPSS 4.3%8.8CVE-2018-0387Cisco webex teams improper input validation vulnerabilityA vulnerability in Cisco Webex Teams (for Windows and macOS) could allow an unauthenticated, remote attacker to execute arbitrary code on the user's …EPSS 3.1%8.7CVE-2018-0436Cisco webex teams improper access control vulnerabilityA vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization…EPSS 1.3%8.4CVE-2020-3535Cisco webex teams uncontrolled search path element vulnerabilityA vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to…EPSS 0.59%7.8CVE-2021-1536Cisco webex meetings desktop uncontrolled search path element vulnerabilityA vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and C…EPSS 0.33%7.8CVE-2021-1502Cisco webex meetings desktop memory buffer overflow vulnerabilityA vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to…EPSS 1.1%7.4CVE-2020-3155Cisco intelligence proximity improper certificate validation vulnerabilityA vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alte…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2019-1636), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.