CVE-2021-1471: Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1471?
CVE-2021-1471 is a vulnerability in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms that could allow an attacker to execute arbitrary programs with elevated privileges.
What versions of Cisco Jabber are affected by CVE-2021-1471?
Versions up to 12.1.5 for Windows, up to 12.8.7 for MacOS, up to 12.9.0 for Android, and up to 12.9.0 for iPhone OS are affected.
What is the severity of CVE-2021-1471?
CVE-2021-1471 has a severity rating of 5.6, which is considered critical.
How can an attacker exploit CVE-2021-1471?
An attacker can exploit CVE-2021-1471 by executing arbitrary programs on the underlying operating system with elevated privileges.
Is there a fix for CVE-2021-1471?
Yes, Cisco has released software updates to address the vulnerability. It is recommended to update to the latest version of Cisco Jabber.