PT-2020-5278 · Cisco · Cisco Jabber For Windows+2
Published
2020-12-10
·
Updated
2020-12-12
·
CVE-2020-27127
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Jabber for Windows (affected versions not specified)
Cisco Jabber for MacOS (affected versions not specified)
Cisco Jabber for mobile platforms (affected versions not specified)
Description
The issue is related to multiple vulnerabilities in Cisco Jabber that could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges or gain access to sensitive information. One of the vulnerabilities is associated with inadequate access control. Exploitation of this vulnerability could allow a remote attacker to gain unauthorized access to protected information.
Recommendations
For Cisco Jabber for Windows, update to a version that addresses the vulnerabilities.
For Cisco Jabber for MacOS, update to a version that addresses the vulnerabilities.
For Cisco Jabber for mobile platforms, update to a version that addresses the vulnerabilities.
As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation.
Fix
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Jabber For Macos
Cisco Jabber For Windows
Cisco Jabber For Mobile Platforms