CVE-2019-1674 is a privilege escalation vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows. It allows an authenticated, local attacker to execute arbitrary commands with SYSTEM privileges due to insufficient validation of user-supplied parameters. The vulnerability has a CVSS score of 8.8 (High) and can be exploited remotely in Active Directory environments. While not actively exploited in the wild (KEV), public exploit code is available (EDB-46479), and it has garnered significant community discussion and media coverage. Cisco has released patches in Webex Meetings Desktop App Release 33.6.6 and 33.9.1, and Webex Productivity Tools Release 33.0.7.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 33.6.6CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings:*:*:*:*:desktop:*:*:* | ||
t33.0.5CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:t33.0.5:*:*:*:*:*:*:* | ||
t33.6.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:t33.6.0:*:*:*:*:*:*:* | ||
t33.6.1CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:t33.6.1:*:*:*:*:*:*:* | ||
t33.6.2CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:t33.6.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.