Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCisco Jabber
APPCisco< 12.1.4< 12.8.5< 12.9.412.5 – 12.5.3 (excl.)12.6 – 12.6.4 (excl.)12.7 – 12.7.3 (excl.)12.8 – 12.8.4 (excl.)12.9 – 12.9.3 (excl.)12.9 – 12.9.4 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
Related vulnerabilities
CVE-2021-1418CRITICAL9.9PL ✓same product
Cisco Jabber — wielokrotne podatności umożliwiające RCE i DoS
CVE-2021-1469CRITICAL9.9PL ✓same product
Wiele podatności w Cisco Jabber umożliwiających RCE z podwyższonymi uprawnieniami
CVE-2021-1411CRITICAL9.9PL ✓same product
Cisco Jabber – krytyczne podatności umożliwiające RCE z podwyższonymi uprawnieniami
CVE-2021-1417CRITICAL9.9PL ✓same product
Krytyczne podatności w Cisco Jabber — eskalacja uprawnień i DoS
CVE-2021-1471CRITICAL9.9PL ✓same product
Cisco Jabber — wielokrotne podatności RCE, ujawnienie danych i DoS