PT-2020-5278 · Cisco · Cisco Jabber For Windows+2

Published

2020-12-10

·

Updated

2020-12-12

·

CVE-2020-27127

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Jabber for Windows (affected versions not specified) Cisco Jabber for MacOS (affected versions not specified) Cisco Jabber for mobile platforms (affected versions not specified)
Description The issue is related to multiple vulnerabilities in Cisco Jabber that could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges or gain access to sensitive information. One of the vulnerabilities is associated with inadequate access control. Exploitation of this vulnerability could allow a remote attacker to gain unauthorized access to protected information.
Recommendations For Cisco Jabber for Windows, update to a version that addresses the vulnerabilities. For Cisco Jabber for MacOS, update to a version that addresses the vulnerabilities. For Cisco Jabber for mobile platforms, update to a version that addresses the vulnerabilities. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation.

Fix

Improper Access Control

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00007
CVE-2020-27127

Affected Products

Cisco Jabber For Macos
Cisco Jabber For Windows
Cisco Jabber For Mobile Platforms