Cisco has addressed a critical arbitrary program execution issue, tracked as CVE-2021-1411, that affects several versions of Cisco Jabber client software for Windows, Android, and iOS. The issue stems from the improper input validation of incoming messagess contents and was rated by Cisco with a CVSS score of 9.9 out of 10. The vulnerability can be only exploited by attackers that are authenticated to an XMPP server used by the vulnerable software. The flaw was reported by Olav Sortland Thoresen of Watch.com.”]
Source: https://securityaffairs.co/wordpress/115931/security/cisco-jabber-critical-flaw.html

