Vulnerability record · CVE-2020-3495 · published 4 September 2020
CVE-2020-3495: Cisco Jabber for Windows XMPP message validation flaw allows code execution
Cisco · Jabber
Cisco Jabber for Windows fails to properly validate the contents of XMPP messages, so a crafted message can cause the client to execute arbitrary programs. Because the flaw is reachable over the network by an authenticated attacker and runs code with the victim user's privileges, it is a serious risk on any network where Jabber messaging is used.
Description
A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages to the affected software. A successful exploit could allow the attacker to cause the application to execute arbitrary programs on the targeted system with the privileges of the user account that is running the Cisco Jabber client software, possibly resulting in arbitrary code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with high confidentiality, integrity and availability impact and a high EPSS score, though it requires an authenticated attacker and no public exploit is documented.
What it is
Cisco Jabber for Windows fails to properly validate the contents of XMPP messages, so a crafted message can cause the client to execute arbitrary programs. Because the flaw is reachable over the network by an authenticated attacker and runs code with the victim user's privileges, it is a serious risk on any network where Jabber messaging is used.
Impact
An attacker gains arbitrary code execution on the targeted system with the privileges of the user running the Jabber client, which can lead to full compromise of that user's data and session.
Attack surface
The vulnerability is reached remotely over the network by sending specially crafted XMPP messages to the affected software. The CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N), so the attacker must be an authenticated party able to deliver messages to the client.
Exploitation
CVE-2020-3495 is not listed in CISA KEV, but EPSS is high at roughly 0.599 probability over 30 days (99th percentile), suggesting elevated likelihood of exploitation activity. The only references are Cisco vendor advisories, which do not document public exploit code or in-the-wild use.
What to do
- Apply the Cisco security advisory fix for Jabber for Windows as the first action.
- Restrict who can send XMPP messages to Jabber clients and limit federation or external messaging where not needed.
- Run Jabber clients with least-privilege user accounts to reduce the impact of code execution.
- Monitor Cisco advisories for updated fixed versions and confirm deployed client builds are patched.
Detection
- Alert on Jabber client processes spawning unexpected child processes such as cmd.exe, powershell.exe or script interpreters.
- Monitor network traffic for anomalous or malformed XMPP message content directed at Jabber clients.
- Review endpoint logs for unusual file writes or executions originating from the Jabber client process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-3495 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3495), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.