CVE-2019-1927: Cisco Webex Business Suite

High severity, CVSS 7.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.

Affected products

  • Cisco Webex Business Suite: before 39.5.5 (fixed in 39.5.5)
  • Cisco Webex Meetings Online: before 1.3.43 (fixed in 1.3.43)
  • Cisco Webex Meetings Server: version 2.8 only; version 3.0 only; version 3.0mr2 only; version 4.0 only

Published 2019-08-07. Last modified 2026-06-17.