Vulnerability record · CVE-2019-1636 · published 23 January 2019
CVE-2019-1636: Cisco Webex Teams Windows client unsafe search path allows command execution
Cisco · Webex Teams
The Cisco Webex Teams (formerly Spark) Windows client uses unsafe search paths for its application URI, so it can load libraries from a directory controlled via a crafted link. An attacker who convinces a user to follow a malicious link and can place a crafted library in a reachable directory may get code to run. It matters because the client runs with the user's privileges and the flaw is trivially triggered by a link.
Description
A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows operating systems. An attacker could exploit this vulnerability by convincing a targeted user to follow a malicious link. Successful exploitation could cause the application to load libraries from the directory targeted by the URI link. The attacker could use this behavior to execute arbitrary commands on the system with the privileges of the targeted user if the attacker can place a crafted library in a directory that is accessible to the vulnerable system.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity and availability impact and a very high EPSS score, though exploitation requires user interaction and local library placement.
What it is
The Cisco Webex Teams (formerly Spark) Windows client uses unsafe search paths for its application URI, so it can load libraries from a directory controlled via a crafted link. An attacker who convinces a user to follow a malicious link and can place a crafted library in a reachable directory may get code to run. It matters because the client runs with the user's privileges and the flaw is trivially triggered by a link.
Impact
An attacker can execute arbitrary commands on the targeted system with the privileges of the targeted user, giving code execution in that user's context.
Attack surface
Reached locally through the Windows application URI handler; the CVSS vector is AV:L with UI:R and PR:N, so no authentication is needed but the victim must follow a malicious link and a crafted library must be placed in a directory accessible to the system.
Exploitation
Not listed in CISA KEV and no ransomware use is documented; EPSS is high (0.46891, 98.8th percentile), and references are only vendor and third-party advisories with no public exploit tag.
What to do
- Apply the Cisco advisory fix for the Webex Teams client (cisco-sa-20190123-webex-teams) and update to a corrected release.
- Restrict write access to directories the client searches so untrusted users cannot plant libraries.
- Warn users not to follow unsolicited Webex Teams or Spark URI links.
- Where feasible, limit or disable the Webex Teams URI handler until patched.
Detection
- Monitor for unexpected DLL or library loads by the Webex Teams client from user-writable or unusual directories.
- Alert on Webex Teams/Spark URI handler launches originating from email, chat or web links.
- Audit file creation of libraries in directories reachable by the client for suspicious names or unsigned binaries.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/106718 | Third Party Advisory |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-webex-teams | Vendor Advisory |
| http://www.securityfocus.com/bid/106718 | Third Party Advisory |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-webex-teams | Vendor Advisory |
Track CVE-2019-1636 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1636), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.