First published: Wed Mar 24 2021(Updated: )
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-jabber-PWrTATTC
Credit: Olav Sortland Thoresen Watchcom for reporting the following vulnerabilitiesCVE-2021-1417 CVE-2021-1418. The following vulnerabilities were found during internal security testing: CVE-2021-1469 CVE-2021-1471.
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Jabber for Windows | =12.9<12.9.5=12.8<12.8.5=12.7<12.7.4=12.6<12.6.5=12.5<12.5.4>=.1<12<=12.1<12.1.5 | 12.9.5 12.8.5 12.7.4 12.6.5 12.5.4 12.1.5 |
Cisco Jabber for MacOS | =12.9<12.9.6>=12.7 and earlier<=12.8<12.8.7 | 12.9.6 12.8.7 |
Cisco Jabber for Android and iOS | ||
Cisco Jabber | =12.9<12.9.1 | 12.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for this Cisco Jabber vulnerability is cisco-sa-cisco-jabber-PWrTATTC.
The severity level of the vulnerability cisco-sa-cisco-jabber-PWrTATTC is critical.
The versions 12.9, 12.8, 12.7, 12.6, 12.5, and 12.1 of Cisco Jabber for Windows are affected by this vulnerability.
The versions 12.9, 12.7 and earlier, and 12.8 of Cisco Jabber for MacOS are affected by this vulnerability.
All versions of Cisco Jabber for Android and iOS are affected by this vulnerability.
An attacker can exploit this vulnerability to execute arbitrary programs with elevated privileges, access sensitive information, intercept network traffic, and more.
More information about this vulnerability can be found at the following link: [Cisco Security Advisory cisco-sa-cisco-jabber-PWrTATTC](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-jabber-PWrTATTC)