9
CVSSv2

CVE-2021-1411

Published: 24/03/2021 Updated: 29/03/2021
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 9.9 | Impact Score: 6 | Exploitability Score: 3.1
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an malicious user to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco jabber

Vendor Advisories

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition For ...

Recent Articles

Patch alert for Apple fans: Cybercrooks have already been exploiting this flaw in iPhones, iPads, and watches
The Register • Iain Thomson in San Francisco • 29 Mar 2021

Plus: Did Google expose a Western spying op? Who cares? You're safer

In brief Apple has issued critical security patches for all supported phones, fondleslabs, and watches after being alerted to multiple possible intrusions by Google.
The fix issued on Friday for iOS 14.4.2 and iPadOS 14.4.2, CVE-2021-1879, is urgently needed. According to Apple, the flaw allows for the creation of "maliciously crafted web content," which "may lead to universal cross-site scripting." Apple has heard that the code snafu "may have been actively exploited."
To make matte...

Cisco addresses critical bug in Windows, macOS Jabber clients
BleepingComputer • Sergiu Gatlan • 24 Mar 2021

Cisco has addressed a critical arbitrary program execution vulnerability impacting several versions of Cisco Jabber client software for Windows, macOS, Android, and iOS.
is a web conferencing and instant messaging app that allows users to send messages via the Extensible Messaging and Presence Protocol (XMPP).
The vulnerability was reported by Olav Sortland Thoresen of Watchcom. Cisco's Product Security Incident Response Team (PSIRT) says that the flaw is not currently exploited in ...

The Register

In brief Apple has issued critical security patches for all supported phones, fondleslabs, and watches after being alerted to multiple possible intrusions by Google.
The fix issued on Friday for iOS 14.4.2 and iPadOS 14.4.2, CVE-2021-1879, is urgently needed. According to Apple, the flaw allows for the creation of "maliciously crafted web content," which "may lead to universal cross-site scripting." Apple has heard that the code snafu "may have been actively exploited."
To make matte...