Advisory:
Critical Cisco Jabber Bug Allows Authenticated, Remote Attacker Hack Systems

Cornerstone.IT Gold Microsoft Partner

Connect with us at

www.Cornerstone.IT/contact for the latest updates.

Keeshia Leopoldo, InfoSec Team Lead, Cornerstone.IT

Who is affected?
Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile

Ask us how we can help secure your environment with the top 10-12 security enhancements every firm should have.  #ITCornerView

Issue/Vulnerability

Critical Cisco Jabber Bug Allows Authenticated, Remote Attacker Hack Systems


Scope

Cisco has released an advisory for multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. CISA encourages users and administrators to review the Cisco Security Advisories page and apply the necessary updates.


Who is affected?

Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile.

Cisco Jabber PlatformAssociated CVE IDs
WindowsCVE-2021-1411, CVE-2021-1417, CVE-2021-1418, CVE-2021-1469, and CVE-2021-1471
MacOSCVE-2021-1418 and CVE-2021-1471
Android and iOSCVE-2021-1418 and CVE-2021-1471

Remediation/Action Plan

Customers are advised to upgrade to an appropriate fixed software release as indicated in the following tables:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-jabber-PWrTATTC

Cisco Jabber for Windows

Cisco Jabber for Windows ReleaseFirst Fixed Release
Earlier than 12.1Migrate to a fixed release.
12.112.1.5
12.512.5.4
12.612.6.5
12.712.7.4
12.812.8.5
12.912.9.5

Cisco Jabber for MacOS

Cisco Jabber for MacOS ReleaseFirst Fixed Release
12.7 and earlierMigrate to a fixed release.
12.812.8.7
12.912.9.6

Cisco Jabber for Android and iOS

Cisco Jabber for Android and iOS ReleaseFirst Fixed Release
12.9 and earlierMigrate to a fixed release.
14.01Not vulnerable.

Cisco Jabber for BlackBerry and Cisco Jabber for Intune MAM

Cisco JabberFirst Fixed Release
12.912.9.1

#LegalIT #ITCornerView

Cornerstone.IT graphic

Cornerstone.IT