Cisco faced a new remote code execution vulnerability of critical severity (RCE) that affects several versions of Cisco Jabber for Windows, macOS and mobile platforms after the remediation of a related security flaw in September.
Cisco Jabber is a desktop instant messaging and web conferencing application that was built using the Chromium Embedded Framework (CEF).
The application provides messaging between users using the Extensible Messaging and Presence Protocol (XMPP) and also provides them with presentation and desktop sharing capabilities

RCE caused by insufficient mitigation
Cisco released some security updates in September to address a critical RCE security vulnerability named as CVE-2020-3495 and stemmed from a Cross-Site Scripting (XSS) in Cisco Jabber.
Since then, a new RCE vulnerability has been found by Watchcom researchers who reported it to Cisco after checking whether the September patch fully fixed CVE-2020-3495
“During this audit, we discovered that some more serious vulnerabilities, including the RCE vulnerability, have not been properly mitigated and that users remain vulnerable,” says Watchcom.
“The patches are now available and we urge all Cisco Jabber users to update as soon as possible!”
In total, researchers reported four client vulnerabilities in Cisco Jabber in September, and they found that three of them were not adequately mitigated by Cisco patches
This allowed them to identify new vulnerabilities that could be abused to exploit all currently supported versions of Cisco Jabber (from version 12.1 all the way up to 12.9).
Information source: bleepingcomputer.com
