cbcvebase.
CVE-2020-3430
published 2020-09-04

CVE-2020-3430: A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to execute arbitrary…

PriorityP260high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.90%
89.1th percentile
A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper handling of input to the application protocol handlers. An attacker could exploit this vulnerability by convincing a user to click a link within a message sent by email or other messaging platform. A successful exploit could allow the attacker to execute arbitrary commands on a targeted system with the privileges of the user account that is running the Cisco Jabber client software.

Affected

8 ranges
VendorProductVersion rangeFixed in
ciscocisco_jabber
ciscojabber>= 12.1 < 12.1.312.1.3
ciscojabber>= 12.5 < 12.5.212.5.2
ciscojabber>= 12.6 < 12.6.312.6.3
ciscojabber>= 12.7 < 12.7.212.7.2
ciscojabber>= 12.8 < 12.8.312.8.3
ciscojabber>= 12.9 < 12.9.112.9.1
ciscojabber_for_windows_protocol_handler

Detection & IOCsextracted from sources · hover to see the quote

  • The attack vector is a malicious link delivered via email or other messaging platform that triggers Cisco Jabber's application protocol handler, leading to command injection. Monitor for suspicious invocations of Cisco Jabber protocol handlers (e.g., jabber://, xmpp://) originating from user clicks in email or messaging clients.
  • The vulnerability is classified as OS Command Injection (CWE-78) via improper input handling in Cisco Jabber for Windows protocol handlers. Detect unexpected child processes spawned by the Cisco Jabber client process, which may indicate successful command injection.
  • Successful exploitation results in arbitrary command execution under the privileges of the Jabber user account. Alert on cmd.exe, powershell.exe, or other shells spawned as child processes of the Cisco Jabber executable.
  • ·No workarounds are available for this vulnerability; patching is the only remediation. Ensure Cisco Jabber for Windows is updated to a fixed version as released by Cisco (tracked under Bug ID CSCvu96368).

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.