Rapid7 Vulnerability & Exploit Database

Cisco Jabber: CVE-2020-3495: A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Cisco Jabber: CVE-2020-3495: A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
09/02/2020
Created
09/05/2020
Added
09/04/2020
Modified
10/15/2020

Description

A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages to the affected software. A successful exploit could allow the attacker to cause the application to execute arbitrary programs on the targeted system with the privileges of the user account that is running the Cisco Jabber client software, possibly resulting in arbitrary code execution.

Solution(s)

  • cisco-jabber-upgrade-12_1_3
  • cisco-jabber-upgrade-12_5_2
  • cisco-jabber-upgrade-12_6_3
  • cisco-jabber-upgrade-12_7_2
  • cisco-jabber-upgrade-12_8_3
  • cisco-jabber-upgrade-12_9_1

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;