Jabber IM Client for Windows Has a Critical Flaw; Update Now

Please be advised of an exploit requiring no user interaction, which affects Cisco Jabber for Windows in which XMPP messaging services are enabled. Systems using Cisco Jabber in phone-only mode (without XMPP messaging services enabled) are not vulnerable to the exploit and Cisco additionally advises that the vulnerability is not a threat when Cisco Jabber is configured to use messaging services other than XMPP messaging.

This vulnerability impacts Cisco Jabber 12.1 – 12.9 and is being tracked as CVE 2020 3495, with a severity score of 9.9/10, and allows for remote code execution with the privileges of the targeted user. Users are advised to update immediately. The following is a table which contains the corresponding update for each release.

12.1=>12.1.3; 12.5=>12.5.2; 12.6=>12.6.3; 12.7=>12.7.2; 12.8=>12.8.3; 12.9=>12.9.1

Image courtesy of CISCO

Please note that this vulnerability does not affect Jabber for MacOS or mobile platforms. 

Resources: