801
VMScore

CVE-2020-27127

Published: 11/12/2020 Updated: 07/11/2023
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 9.9 | Impact Score: 6 | Exploitability Score: 3.1
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an malicious user to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco jabber 12.9\\(0\\)

cisco jabber 12.9\\(1\\)

cisco jabber 12.9\\(2\\)

cisco jabber 12.9\\(3\\)

cisco jabber for mobile platforms 12.9\\(0\\)

cisco jabber for mobile platforms 12.9\\(1\\)

cisco jabber for mobile platforms 12.9\\(2\\)

cisco jabber for mobile platforms 12.9\\(3\\)

Vendor Advisories

Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information For more information about these vulnerabilities, see the Details section of this adv ...

Recent Articles

The patch that wasn't: Cisco emits fresh fixes for NTLM hash-spilling vuln and XSS-RCE combo in Jabber app
The Register • Gareth Corfield • 10 Dec 2020

Wormable nasty still doesn't need any user input to pwn target devices

A previous patch for Cisco's Jabber chat product did not in fact fix four vulnerabilities – including one remote code execution (RCE) flaw that would allow malicious people to hijack targeted devices by sending a carefully crafted message. Norwegian infosec biz Watchcom spotted the vulnerabilities, having been asked by a client to verify that a previous patch for CVE-2020-26085 worked as advertised. Instead Watchcom found that the September update didn't fix the underlying problems. A cross-si...