Cisco patches critical, wormable RCE flaw in Cisco Jabber

Read the original article: Cisco patches critical, wormable RCE flaw in Cisco Jabber


Cisco has patched four vulnerabilities in its Jabber client for Windows, the most critical of which (CVE-2020-3495) could allow attackers to achieve remote code execution by sending specially crafted chat messages. “No user interaction is required, and the vulnerability can be exploited even when Cisco Jabber is running in the background,” Oslo-based cybersecurity company Watchcom explained. That particular flaw is also wormable, they say. CVE-2020-3495 Cisco Jabber is a video conferencing and instant messaging application … More

The post Cisco patches critical, wormable RCE flaw in Cisco Jabber appeared first on Help Net Security.


Read the original article: Cisco patches critical, wormable RCE flaw in Cisco Jabber