Lucene search

K
ciscoCiscoCISCO-SA-20140115-CVE-2014-0666
HistoryJan 15, 2014 - 10:43 p.m.

Cisco Jabber for Windows Remote Code Execution Vulnerability

2014-01-1522:43:55
tools.cisco.com
13

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.026

Percentile

90.3%

A vulnerability in the Send Screen Capture function of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to install arbitrary files on a targeted system.

The vulnerability is due to insufficient validation of data in the packets sent via the send screen capture functionality. An attacker could exploit this vulnerability by crafting or altering the packets sent as part of a send screen capture that would result in an uncontrolled directory traversal and/or acceptance of non-graphic type files. An exploit could allow the attacker to potentially execute arbitrary code on the Windows machine with the privileges of the installed Cisco Jabber for Windows client software.

Cisco has confirmed the vulnerability in a security notice and released software updates.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscojabberMatchanywindows
OR
ciscojabberMatchanywindows
VendorProductVersionCPE
ciscojabberanycpe:2.3:a:cisco:jabber:any:*:*:*:*:windows:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.026

Percentile

90.3%

Related for CISCO-SA-20140115-CVE-2014-0666