CVE-2025-20236
Cisco Webex App Client-Side Remote Code Execution Vulnerability
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-10-10 CVE Reserved
- 2025-04-16 CVE Published
- 2025-04-17 CVE Updated
- 2025-04-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-client-rce-ufyMMYLC |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Cisco Webex Teams Search vendor "Cisco" for product "Cisco Webex Teams" | 44.6 Search vendor "Cisco" for product "Cisco Webex Teams" and version "44.6" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Webex Teams Search vendor "Cisco" for product "Cisco Webex Teams" | 44.6.0.29928 Search vendor "Cisco" for product "Cisco Webex Teams" and version "44.6.0.29928" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Webex Teams Search vendor "Cisco" for product "Cisco Webex Teams" | 44.6.0.30148 Search vendor "Cisco" for product "Cisco Webex Teams" and version "44.6.0.30148" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Webex Teams Search vendor "Cisco" for product "Cisco Webex Teams" | 44.7 Search vendor "Cisco" for product "Cisco Webex Teams" and version "44.7" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Webex Teams Search vendor "Cisco" for product "Cisco Webex Teams" | 44.7.0.30141 Search vendor "Cisco" for product "Cisco Webex Teams" and version "44.7.0.30141" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Webex Teams Search vendor "Cisco" for product "Cisco Webex Teams" | 44.7.0.30285 Search vendor "Cisco" for product "Cisco Webex Teams" and version "44.7.0.30285" | en |
Affected
|