Security News > 2020 > September > Attackers Can Exploit Critical Cisco Jabber Flaw With One Message

Attackers Can Exploit Critical Cisco Jabber Flaw With One Message
2020-09-03 17:30

Researchers are warning of a critical remote code-execution flaw in the Windows version of Cisco Jabber, the networking company's video-conferencing and instant-messaging application.

The flaw has a CVSS score of 9.9 out of 10, making it critical in severity, Cisco said in a Wednesday advisory.

An attacker could exploit the flaw by sending specially crafted Extensible Messaging and Presence Protocol messages to vulnerable end-user systems running Cisco Jabber for Windows.

The issue stems from Cisco Jabber improperly validating message contents; the application does not properly sanitize incoming HTML messages.

Cisco has released updates for different releases of affected Cisco Jabber.


News URL

https://threatpost.com/attackers-can-exploit-critical-cisco-jabber-flaw-with-one-message/158942/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Cisco 4448 234 3132 1870 609 5845