← Vulnerability feed

Vulnerability record · CVE-2020-3535 · published 8 October 2020

CVE-2020-3535: Cisco webex teams uncontrolled search path element vulnerability

Cisco · Webex Teams

A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a malicious library. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. The vulnerability is due to incorrect handling of directory paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file in a specific location on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with the privileges of another user’s account.

8.4 CVSS 3.1 High EPSS 0.59% · top 53.8% CWE-427 · Uncontrolled search path element
8.4CVSS 3.1 base score, v2 7.2
0.59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a malicious library. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. The vulnerability is due to incorrect handling of directory paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file in a specific location on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with the privileges of another user’s account.

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3535 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-20236Cisco webex teams inclusion from untrusted sphere vulnerabilityA vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary …EPSS 0.97%8.8CVE-2019-1939Cisco webex teams injection vulnerabilityA vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affec…EPSS 4.3%8.8CVE-2018-0387Cisco webex teams improper input validation vulnerabilityA vulnerability in Cisco Webex Teams (for Windows and macOS) could allow an unauthenticated, remote attacker to execute arbitrary code on the user's …EPSS 3.1%8.7CVE-2018-0436Cisco webex teams improper access control vulnerabilityA vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization…EPSS 1.3%7.8CVE-2021-1536Cisco webex meetings desktop uncontrolled search path element vulnerabilityA vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and C…EPSS 0.33%7.8CVE-2021-1502Cisco webex meetings desktop memory buffer overflow vulnerabilityA vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to…EPSS 1.1%7.8CVE-2019-1636Cisco Webex Teams Windows client unsafe search path allows command executionThe Cisco Webex Teams (formerly Spark) Windows client uses unsafe search paths for its application URI, so it can load libraries from a directory con…EPSS 47%analysed7.4CVE-2020-3155Cisco intelligence proximity improper certificate validation vulnerabilityA vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alte…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2020-3535), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.