CVE-2019-1925 describes multiple vulnerabilities in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows, affecting Webex Business Suite, Meetings Online, and Meetings Server. These flaws stem from improper validation of Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit this by tricking a user into opening a malicious ARF or WRF file, leading to arbitrary code execution with the user's privileges. Rated 7.8 HIGH on CVSS, this vulnerability requires user interaction (UI:R) and local access (AV:L) but has low attack complexity (AC:L), with potential for high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 39.5.5CPE matchmatch criteria | cpe:2.3:a:cisco:webex_business_suite:*:*:*:*:*:*:*:* | ||
< 1.3.43CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_online:*:*:*:*:*:*:*:* | ||
2.8CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:2.8:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:3.0:*:*:*:*:*:*:* | ||
3.0mr2CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:3.0mr2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.