CVE-2020-3263 is a high-severity vulnerability in the Cisco Webex Meetings Desktop App that allows an unauthenticated, remote attacker to execute programs on an affected end-user system. The flaw stems from improper validation of input supplied to application URLs, which an attacker could exploit by tricking a user into clicking a malicious link. Successful exploitation could lead to the execution of existing programs or arbitrary code if malicious files are present. While not actively exploited in the wild and lacking public exploit code, the vulnerability has garnered significant community discussion and media attention, indicating its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 39.5.12CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings:*:*:*:*:desktop:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.